Skills
Deep Scan
Deep Scan for AI Agent Components
Review skills, plugins, agents, and MCP servers for documented component risks before they become trusted dependencies.
A scan result supports review; it does not guarantee that a component or its future behavior is safe.
Components and Risks
The public product surface names four component types and four risk categories for Deep Scan.
Plugins
Agents
MCP Servers
Prompt Injection
Malicious Tools
Credential Leaks
These documented categories are not a complete detection taxonomy or a coverage guarantee.
Choose a Scan Path
Identify the repository, package, MCP server, URL, skill, plugin, or agent you need to review.
Follow the supported CLI, Quickstart, or API path available for that component.
Review the finding with component provenance, permissions, dependencies, and configuration in view.
The public API Reference lists repository, package, MCP-server, and URL scan endpoints. Live request and response behavior has not been verified in this audit.
Review the Findings
Lifecycle Scanning
Before Trust
Use Deep Scan to review a component before it becomes a dependency.
Review the component again when its source, package, permissions, or configuration changes.
Use Runtime Guard where the selected integration can evaluate documented high-risk actions.
Explore Runtime Guard
Frequently Asked Questions
Which components can Deep Scan review?
Which risks are documented?
Does a clean scan guarantee safety?
Which package ecosystems are supported?
Review Before Trust
Use the documented integration, verify expected outcomes, and record any action that remains outside the control path.