Open-source CLI audits AI tools, MCP configs, and agent skills on local machines

Initial-Copy332 · reddit · 2026-07-21

The author released an open-source, local-first CLI for auditing the AI tooling on a developer machine.

It can check installed AI development tools, MCP config locations, process/network posture, and local agent skills without calling an LLM or requiring an account. The broader toolchain also includes static scanning for agent code, red-teaming agents or MCP servers, and a proxy to observe or enforce policy on MCP traffic.

The motivation is supply-chain and agent-security visibility: attacks have searched developer machines for Claude/Gemini/Q config files and auth tokens, and malicious skills have appeared in marketplaces. The author asks for feedback on false classifications, unsupported paths, and ways to evade the threat model.

Original post →

More from coding & agent

coding & agent channel →