Skip to main content
SEP 2026 Latest guide updates. Latest: Skill Governance Skill Lifecycle Skills vs Harnesses Changelog →

Security hub

Secure Claude Code and AI Agents

Start with a local repository check, review current evidence, then follow the security path that matches your task.

Threat DB v2.29.0Updated September 12, 2026

Local check

Start with your repository

Install AgentSec and run its current alpha scanner locally. This website does not receive or inspect your files.

AgentSec 0.1.0a0
agentsec scan /path/to/repository --format json --redact

Current evidence, with its date

These values come from the bundled AgentSec feed and describe that database snapshot. They are not live measurements of the entire ecosystem.

Skills Scanned
3,984
Have Flaws
36.82%
Critical-Risk
534
Malicious Payloads
76
CVEs & Advisories
131
Exposed Servers
~1,000

Verify your repository with AgentSec

The scanner checks bounded repository inputs against bundled intelligence. A clean result is not proof of safety.

3. Respect the boundary

Current detectors do not cover every host-level persistence mechanism, Git-history witness, or runtime behavior.

2 detector records
  • clawhavoc-skill v1: Detect repository-local agent-skill evidence associated with the documented ClawHavoc fake-prerequisite campaign.
  • shai-hulud-keyv v1: Detect repository-local indicators associated with the August 2026 Shai-Hulud Keyv/cacheable npm campaign.

Latest sourced intelligence

Three recent feed events, ordered by their canonical date. Follow the source before making a time-sensitive decision.

VS Code: Webview resource root escape

A webview using non-file resource schemes can exploit inconsistent separator handling to read content outside the extension's allowed resource roots.

VS Code: Copilot Chat ADO token endpoint override

Repository settings can redirect authenticated Azure DevOps Code Search requests to an attacker endpoint and expose the user's token.

VS Code: Chat remote media request before filtering

Rendering agent-provided remote media can initiate a request before the chat policy removes the element, potentially leaking data encoded in its URL, including on history restoration.

Open all threat intelligence β†’

Three checks before you continue

Use this quick pass now. The full hardening route keeps the complete workstation and team checklist.

0 of 3 complete

Repository
Runtime
Team controls

Open the complete checklist β†’