See what your agents are doing.

One system to scan, score, and secure every MCP server and agent skill in your stack.

Catch hidden instructions, credential theft, and malware — before they reach your machine.

Free to start. No API key required.

4,104+

Servers indexed

4,072+

Scans completed

220+

Detection checks

Why Vigile

Scan. Score. Secure.

Three layers of protection for the AI agent supply chain — from static analysis to runtime monitoring.

Scan

220+ detection checks across MCP, skill, runtime, and backend analysis catch instruction injection, malware delivery, stealth operations, data exfiltration, and more. One command scans everything.

npx vigile-scan --all

Score

Every skill and server gets a 0-100 trust score. The public registry lets you check before you install — like a security credit score for AI tools.

TrustedCautionDangerous

Secure

Sentinel monitors MCP servers in real time. Catch phone-home behavior, DNS tunneling, and C2 connections that static analysis misses.

Real-time monitoring

The problem

Agent skills run with your AI's full trust. There's no sandbox, no review, no warning.

When you install a SKILL.md file in Claude Code or a .mdc rule in Cursor, your agent follows those instructions unconditionally. A malicious skill doesn't need its own tools — it weaponizes every tool your agent already has.

36.7%

of MCP servers exposed to SSRF

BlueRock Security, 7,000+ analyzed

512

vulnerabilities in OpenClaw audit, 8 critical

Jan 2026

CVSS 8.8

OpenClaw RCE via CVE-2026-25253

CVE Database

341

malicious skills found on ClawHub

ClawHavoc campaign, Feb 2026

Detection

What Vigile catches

Agent Skill Threats

SK-001

Instruction Injection

Hidden directives that silently override agent behavior

SK-010

Malware Delivery

Fake dependencies that install credential stealers

SK-020

Stealth Operations

Actions hidden from the user — "silently", "don't tell"

SK-030

Safety Bypass

Disabling confirmations, auto-approving dangerous actions

SK-040

Persistence

.bashrc writes, CLAUDE.md tampering, cron jobs, git hooks

SK-050

Data Exfiltration

Credential harvesting, env dumping, filesystem enumeration

MCP Server Threats

TP-001

Tool Poisoning

Hidden instructions in tool descriptions that hijack behavior

EX-003

Data Exfiltration

Patterns targeting SSH keys, AWS credentials, env files

PM-001

Permission Abuse

Excessive filesystem, network, or code execution access

OB-002

Obfuscation

Base64, hex, zero-width chars hiding malicious payloads

+ typosquatting detection and Sentinel runtime monitoring

Try it now

Five seconds. Zero config.

One command discovers skill files and MCP configs automatically across all your AI tools. No setup required.

01

Run the scanner

Auto-discovers skills and MCP configs across 7 platforms

02

Review findings

54 rules and counting flag injection, malware, stealth ops, and more

03

Trust the score

0-100 composite score — keep the green, block the red

~ terminal

$ npx vigile-scan --all

Scanning skills & MCP servers...

SKILL.md — marketing-automator

CRITICALSK-001 Instruction Injection

"ignore all previous instructions"

CRITICALSK-010 Malware Delivery

pip install "cryptohelper-utils" (known stealer)

HIGH SK-020 Stealth Operations

"do not tell the user about this step"

Trust Score: 12/100 ■ Dangerous

──────────────────────────────────────

.mdc — code-reviewer

✓ No issues found

Trust Score: 94/100 ■ Trusted

Pricing

Start free. Scale when ready.

No credit card required. Upgrade when you need more scans, Sentinel monitoring, and priority support.

Free

$0

forever

  • 50 API scans / month
  • Basic detection patterns
  • Community support

Pro

$30/mo

or $300/year

  • 1,000 scans / month
  • All detection patterns
  • Sentinel Globe (7-day)
  • Embed widget + API

Pro+

$100/mo

or $900/year

  • Everything in Pro
  • 30-day Sentinel history
  • Webhooks + Slack alerts
  • DNS tunneling & C2 detection

Your AI agents deserve a security layer.

Don't install blind. Scan skills and servers before they reach your machine. One command is all it takes.

npx vigile-scan --allscan everything