Open-source CLI audits AI tools, MCP configs, and agent skills on local machines
Initial-Copy332 · reddit · 2026-07-21
The author released an open-source, local-first CLI for auditing the AI tooling on a developer machine.
It can check installed AI development tools, MCP config locations, process/network posture, and local agent skills without calling an LLM or requiring an account. The broader toolchain also includes static scanning for agent code, red-teaming agents or MCP servers, and a proxy to observe or enforce policy on MCP traffic.
The motivation is supply-chain and agent-security visibility: attacks have searched developer machines for Claude/Gemini/Q config files and auth tokens, and malicious skills have appeared in marketplaces. The author asks for feedback on false classifications, unsupported paths, and ways to evade the threat model.
More from coding & agent
- Devin adds e2b sandboxes for remote agent execution — badphilosopher · 2026-07-22
- Hermes Agent Refactoring Proposal: Decoupling via Event Bus and Monorepo Slicing — Promptmethus · 2026-07-22
- ty now reads Pydantic config keywords and field metadata — charliermarsh · 2026-07-22
- Pensar Launches AI Security Agent to Autonomously Discover and Patch 0-Days — andriy_mulyar · 2026-07-22
- ty adds first-class Pydantic support, including strict and lax field handling — charliermarsh · 2026-07-22
- Google launches Gemini 3.5 Flash Cyber for CodeMender, with limited access for governments — GoogleAI · 2026-07-22