1. Install
Use the projectβs documented installation path, then verify the installed version.
Installation instructions βSecurity hub
Start with a local repository check, review current evidence, then follow the security path that matches your task.
Threat DB v2.29.0Updated September 12, 2026
Local check
Install AgentSec and run its current alpha scanner locally. This website does not receive or inspect your files.
agentsec scan /path/to/repository --format json --redact These values come from the bundled AgentSec feed and describe that database snapshot. They are not live measurements of the entire ecosystem.
The scanner checks bounded repository inputs against bundled intelligence. A clean result is not proof of safety.
Use the projectβs documented installation path, then verify the installed version.
Installation instructions βExecute the scan inside the target repository. Review the exact files and evidence behind each finding.
Inspect AgentSec source βCurrent detectors do not cover every host-level persistence mechanism, Git-history witness, or runtime behavior.
Each route answers one intent completely. The hub keeps orientation and current evidence without repeating every catalogue.
Understand how current attacks work, which ecosystems they affect, and which evidence supports each record.
Open this pathCheck whether a component is affected, inspect the primary source, and find the documented remediation.
Open this pathChoose an isolation boundary, understand what it excludes, and verify the controls before running an agent.
Open this pathReduce immediate risk, strengthen a workstation, and establish repeatable controls for a development team.
Open this pathThree recent feed events, ordered by their canonical date. Follow the source before making a time-sensitive decision.
A webview using non-file resource schemes can exploit inconsistent separator handling to read content outside the extension's allowed resource roots.
Repository settings can redirect authenticated Azure DevOps Code Search requests to an attacker endpoint and expose the user's token.
Rendering agent-provided remote media can initiate a request before the chat policy removes the element, potentially leaking data encoded in its URL, including on history restoration.
Use this quick pass now. The full hardening route keeps the complete workstation and team checklist.
0 of 3 complete
The content remains available at a focused destination. These anchors preserve old bookmarks and inbound links.
Mechanisms, examples, campaigns, and mitigations.
Open threats βSearchable vulnerabilities, fixed-version status, and mitigations.
Open CVEs βDated event records and explicit detector coverage.
Open intelligence βTracked campaign records with reported dates and sources.
Open campaigns βFilter events, campaigns, authors, and malicious skills.
Search threats βProtection boundaries, silent failures, configuration, and runtime checks.
Configure sandbox βCapabilities and limits of the maintained scanner collection.
Compare tools βQuick checks, full audits, and the threat database terminal.
Open commands βDates describe the source record. Recheck the linked source before acting on time-sensitive risk information.