Skip to main content
OCT 2026 Latest guide updates. Latest: Mistral Large 4 AI FinOps Lean & AI Changelog →

Security hub

Secure Claude Code and AI Agents

Start with a local repository check, review current evidence, then follow the security path that matches your task.

Threat DB v2.31.0Updated October 4, 2026

Local check

Start with your repository

Install AgentSec and run its current alpha scanner locally. This website does not receive or inspect your files.

AgentSec 0.1.0a0
agentsec scan /path/to/repository --format json --redact

Current evidence, with its date

These values come from the bundled AgentSec feed and describe that database snapshot. They are not live measurements of the entire ecosystem.

Skills Scanned
3,984
Have Flaws
36.82%
Critical-Risk
534
Malicious Payloads
76
CVEs & Advisories
184
Exposed Servers
~1,000

Verify your repository with AgentSec

The scanner checks bounded repository inputs against bundled intelligence. A clean result is not proof of safety.

3. Respect the boundary

Current detectors do not cover every host-level persistence mechanism, Git-history witness, or runtime behavior.

2 detector records
  • clawhavoc-skill v1: Detect repository-local agent-skill evidence associated with the documented ClawHavoc fake-prerequisite campaign.
  • shai-hulud-keyv v1: Detect repository-local indicators associated with the August 2026 Shai-Hulud Keyv/cacheable npm campaign.

Latest sourced intelligence

Three recent feed events, ordered by their canonical date. Follow the source before making a time-sensitive decision.

Cowork macOS file-open host execution

An omitted executable file type allowed content from a Cowork shared folder to run commands on macOS when opened from Claude Desktop. A separate guest-kernel flaw could remove the user-interaction requirement on older VM images.

MCP Python client external schema reference fetch

Tool output-schema validation resolved server-chosen external references through synchronous URL or local-file reads without a timeout. Retrieved content was used as a schema and was not returned to the server; a stalled fetch could block the event loop.

MCP Python OAuth authorization-server credential confusion

An untrusted MCP server could select where an OAuth client sent credentials because issuer validation and credential binding were incomplete. stdio clients, clients attaching their own headers and SDK servers are excluded.

Open all threat intelligence β†’

Three checks before you continue

Use this quick pass now. The full hardening route keeps the complete workstation and team checklist.

0 of 3 complete

Repository
Runtime
Team controls

Open the complete checklist β†’