# agentscan

Your agent config says the guard is on. The script is gone. Nothing told you.

1.4.0 · 103 checks · offline on check

Linters read the code your agent writes. This reads the agent itself — skills, hooks, MCP servers, lockfiles, and policy files.

## How to run

```bash
npx @chimix/agentscan check
```

Or: `npx @chimix/agentscan@latest`

## How it works

No AI, no network on check. Read the config, read the disk, compare. Same tree in, same findings out, every time.

- 103 checks, each labeled spec-required, vendor-recommendation, security, internal-consistency, or heuristic.
- No network — check never opens a socket.
- Writes nothing — the scanned tree is left untouched.
- Spec-required checks cite a published line in [docs/spec/](https://github.com/SimaAlexandru99/agentscan/tree/master/docs/spec). Heuristics stay at info and are labeled.

## Why the tool looks like this

An earlier build reported 37 findings across 17 real projects of which 25 were false — two checks had been written from what real projects looked like instead of from the spec. Both were deleted. Spec-required checks cite a published line in docs/spec/. Heuristics stay at info and are labeled. 1.0.0 was the first stable release. 1.4.0 ships 103 checks, still offline on check.

## For agents

Agents forget the audit. The skill tells them to run it before they edit a hook or claim a guard is on.

- When: hooks · skills · MCP · AGENTS.md · skills-lock.json
- Do: `npx @chimix/agentscan@latest --output prompt`
- Do not skip `claude.hook.missing-script` (error)
- Don't write the tree or guess if a hook is valid

This origin is a marketing site. There is no hosted HTTP API and no Streamable HTTP MCP server here. MCP in product copy means MCP *configs the CLI audits*.

- [Docs](https://agentscan.space/docs)
- [GitHub](https://github.com/SimaAlexandru99/agentscan)
- [npm @chimix/agentscan](https://www.npmjs.com/package/@chimix/agentscan)
