
AgentShield — AI Skill & MCP Security Scanner
🛡️ AgentShield
Know what an AI Skill can do before you trust it.
AI agents are becoming increasingly powerful — and the Skills, plugins and MCP servers connected to them may execute commands, access files, communicate over the network or interact with sensitive environment variables.
AgentShield analyzes an AI Skill or MCP project before installation and produces a clear, evidence-based security report.
🔍 What it checks
Command & Script Analysis
Detects potentially dangerous shell commands, execution patterns and suspicious scripts.
Permission Analysis
Identifies filesystem, process, network and system capabilities the project may require.
Credential Exposure
Flags suspicious access to environment variables, tokens, keys and credential locations.
Dependency Inspection
Reviews dependency declarations and highlights packages or installation behavior that deserve additional verification.
Network Analysis
Identifies external endpoints and network-related behavior visible in the supplied project.
Skill & MCP Configuration Review
Inspects Skill instructions, MCP configurations and related files for security-sensitive behavior.
Integrity Fingerprinting
Generates hashes for important files so unexpected changes can be detected later.
Version Comparison
Compare two versions and identify security-relevant changes.
📊 Clear Risk Report
Findings are organized as Low, Medium, High or Critical, with the evidence behind each finding and recommended next steps.
AgentShield does not simply label software “safe.” It shows what it found and why it matters, helping you make the final decision.
👨💻 Built for
AI developers, MCP users, Agent builders, Skill publishers and developers installing third-party AI tooling.
🔐 Local-first
Designed for local analysis without requiring a paid external API.
Developer: Mahmoud Hisham
© 2026 Mahmoud Hisham. All rights reserved.


