A security scanner for local AI agent components, MCP servers, and agent skills that detects misconfigurations, risky permissions, secrets exposure, and prompt-injection vulnerabilities before deployment.