1. Install
Use the projectβs documented installation path, then verify the installed version.
Installation instructions βSecurity hub
Start with a local repository check, review current evidence, then follow the security path that matches your task.
Threat DB v2.31.0Updated October 4, 2026
Local check
Install AgentSec and run its current alpha scanner locally. This website does not receive or inspect your files.
agentsec scan /path/to/repository --format json --redact These values come from the bundled AgentSec feed and describe that database snapshot. They are not live measurements of the entire ecosystem.
The scanner checks bounded repository inputs against bundled intelligence. A clean result is not proof of safety.
Use the projectβs documented installation path, then verify the installed version.
Installation instructions βExecute the scan inside the target repository. Review the exact files and evidence behind each finding.
Inspect AgentSec source βCurrent detectors do not cover every host-level persistence mechanism, Git-history witness, or runtime behavior.
Each route answers one intent completely. The hub keeps orientation and current evidence without repeating every catalogue.
Understand how current attacks work, which ecosystems they affect, and which evidence supports each record.
Open this pathCheck whether a component is affected, inspect the primary source, and find the documented remediation.
Open this pathChoose an isolation boundary, understand what it excludes, and verify the controls before running an agent.
Open this pathReduce immediate risk, strengthen a workstation, and establish repeatable controls for a development team.
Open this pathThree recent feed events, ordered by their canonical date. Follow the source before making a time-sensitive decision.
An omitted executable file type allowed content from a Cowork shared folder to run commands on macOS when opened from Claude Desktop. A separate guest-kernel flaw could remove the user-interaction requirement on older VM images.
Tool output-schema validation resolved server-chosen external references through synchronous URL or local-file reads without a timeout. Retrieved content was used as a schema and was not returned to the server; a stalled fetch could block the event loop.
An untrusted MCP server could select where an OAuth client sent credentials because issuer validation and credential binding were incomplete. stdio clients, clients attaching their own headers and SDK servers are excluded.
Use this quick pass now. The full hardening route keeps the complete workstation and team checklist.
0 of 3 complete
The content remains available at a focused destination. These anchors preserve old bookmarks and inbound links.
Mechanisms, examples, campaigns, and mitigations.
Open threats βSearchable vulnerabilities, fixed-version status, and mitigations.
Open CVEs βDated event records and explicit detector coverage.
Open intelligence βTracked campaign records with reported dates and sources.
Open campaigns βFilter events, campaigns, authors, and malicious skills.
Search threats βProtection boundaries, silent failures, configuration, and runtime checks.
Configure sandbox βCapabilities and limits of the maintained scanner collection.
Compare tools βQuick checks, full audits, and the threat database terminal.
Open commands βDates describe the source record. Recheck the linked source before acting on time-sensitive risk information.