Agent Instructions
Finds AGENTS.md, Copilot instructions, custom agents, prompts, and reusable skills.
AI workflow security scanner
Map every place a repository gives AI agents instructions, tools, secrets, or write power, then turn that map into findings, reports, and safer pull request checks.
Finds AGENTS.md, Copilot instructions, custom agents, prompts, and reusable skills.
Reviews GitHub Actions and other workflow files for unsafe agent execution boundaries.
Flags unapproved MCP servers, package launches, command tools, and environment exposure.
--format inventory and inventory-json explain the agentic surface.
--format score gives teams a compact AWI score they can track over time.
--compare old.json new.json shows introduced and resolved findings between scans.
Claude Code, Codex, Cursor, Copilot, Cline, and PR comment bot setup paths.
Commands for SARIF, inventory, score, graph, HTML, migration, compare, and policy reports.
Unsafe real-world patterns maintainers can scan locally without using a private repo.
Command palette scan and Problems panel diagnostics for VS Code.
Local AWI trend dashboard for score, findings, and surface growth.