Before trust

Know what your agents trust. Before they use it.

Inspect skills, MCP servers, agent instructions, plugins, and packages across repositories, pull requests, pipelines, and local workflows.

Supply Chain Security
Illustrative pull request check showing a risky agent component blocked before merge

Know what an agent component can ask for, access, and change.

Turn skills, MCP servers, instructions, plugins, and packages from opaque files into reviewable capabilities and evidence.

01

Inspect agent-native risk

Detect prompt injection, tool poisoning, credential theft, unsafe execution, hidden instructions, and suspicious capability requests.

02

Review meaningful changes

Show what a new version adds, which permissions changed, and where risk entered in one focused review.

03

Enforce every trust gate

Use the same rules in local checks, pull requests, releases, registries, and approved-component workflows.

Check a component before your team trusts it.

Drop in a SKILL.md or MCP configuration. The scan runs locally in your browser and shows the matched rules, severity, evidence, and recommended action.

Loading Platform rules…
01

Give us a file

or paste content
SKILL.md 0 chars

Content is processed on-device and never uploaded.

02

See what shakes out

No mystery box

Every finding shows the rule, severity, matched content, and detection category.

  • Credential exfiltration
  • Prompt injection
  • Unsafe tool use

From unknown component to governed decision.

  1. 01Discover

    Find agent components in repositories, developer machines, pipelines, and connected registries.

  2. 02Analyse

    Inspect instructions, source, configuration, metadata, requested capabilities, and provenance.

  3. 03Gate

    Allow, review, or block adoption and releases according to shared organisational policy.

  4. 04Monitor

    Rescan when components, policies, or threat intelligence change.

Bring security checks into every workflow.

Local

CLI and desktop

Give developers fast, private feedback before a component reaches source control.

Repository

GitHub Apps and PRs

Annotate the changed evidence, enforce policy, and publish SARIF where engineering works.

Delivery

CI/CD and releases

Apply repeatable gates to every change and stop unapproved versions from progressing.

Platform

API and registries

Embed trust decisions in internal catalogs, marketplaces, and custom intake workflows.

Supply Chain Security pull request check with a matched rule and release decision

Show why a component is risky.

Every finding keeps the matched content, rule, severity, category, and recommended action together. Developers can fix the issue; security can defend the decision.

  • Line-level pull-request feedback
  • Capability and permission summaries
  • Version-to-version risk diffs
  • SARIF, JSON, webhooks, and platform APIs
Try the browser scanner

Build a durable trust program.

Continuous rescanning

Re-evaluate components when the rule library or organisational policy changes.

Provenance and signing

Verify origin, approved versions, and integrity before installation or release.

Agent inventory

Track components, owners, locations, versions, and relationships across the estate.

Approved catalog

Give teams a governed path to components that have already passed review.

Policy exceptions

Time-bound accepted risk with ownership, justification, and an audit trail.

Threat intelligence

Map findings to practical agent threats, advisories, CVEs, and control frameworks.

Reduce risk across every stage from one security platform.

Set policy, see coverage, stop high-risk actions, and investigate incidents across every agent and team from one operational view.

01Policy

Author once and adapt decisions to each control point.

02Identity

Connect users, agents, teams, tools, and repositories.

03Evidence

Keep the rule, relevant details, decision, and outcome together.

04Operations

Manage rollout, exceptions, approvals, and reporting.