agentscan

agentscan

Your agent config says the guard is on. The script is gone. Nothing told you.

Linters read the code your agent writes. This reads the agent itself — skills, hooks, MCP servers, lockfiles, and policy files.

1.4.0 · 103 checks · offline on check

npx @chimix/agentscan check
agentscan check
$ agentscan check
 
ERROR rule:claude.hook.missing-script
PreToolUse hook points at a script that does not exist: .claude/hooks/guard-destructive-bash.js
PreToolUse @ .claude/settings.json · .claude/hooks/guard-destructive-bash.js
 
Summary: 1 error · score 90/100

How it works

No AI, no network on check. Read the config, read the disk, compare. Same tree in, same findings out, every time.

  • 103 checks, each labeled spec-required, vendor-recommendation, security, internal-consistency, or heuristic.
  • No network — check never opens a socket.
  • Writes nothing — the scanned tree is left untouched.
  • Spec-required checks cite a published line in docs/spec/. Heuristics stay at info and are labeled.

Why the tool looks like this

An earlier build reported 37 findings across 17 real projects of which 25 were false — two checks had been written from what real projects looked like instead of from the spec. Both were deleted. Spec-required checks cite a published line in docs/spec/. Heuristics stay at info and are labeled. 1.0.0 was the first stable release. 1.4.0 ships 103 checks, still offline on check.

Run it in 30 seconds

Point it at a project with agent config. On Node 20.11+ or Bun — the published bin is a single bundled file.

npx @chimix/agentscan check

For agents

Agents forget the audit. The skill tells them to run it before they edit a hook or claim a guard is on.

skills/agentscan/SKILL.md
When hooks · skills · MCP · AGENTS.md · skills-lock.json
Do npx @chimix/agentscan@latest --output prompt
do not skip claude.hook.missing-script (error)
Don't write the tree · guess if a hook is valid