medusa
AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an always-on AI attack-signature scanner and native Rust & PHP rules. Also: medusa scan --git to vet any repo, medusa secrets scan for leaked API keys. 40,00
MEDUSA is an AI-first security scanner agent that integrates directly into AI coding assistants to detect vulnerabilities in code, AI configurations, and machine learning applications. It features 40,000+ detection patterns covering AI supply chain attacks, prompt injection, MCP server poisoning, and traditional security vulnerabilities across 79 scanner types and 46+ languages. The agent works immediately after installation with no external tool dependencies, supports parallel scanning with smart caching, and integrates natively with Claude Code, Cursor, Gemini CLI, GitHub Copilot, and OpenAI Codex through slash commands and context files.
Key Features
Use Cases
- 01Automatically scan repositories for AI supply chain attacks and weaponized editor configurations before cloning unknown projects
- 02Detect prompt injection, jailbreaks, and indirect PI patterns in AI agent code and RAG pipelines during development
- 03Find and securely redact leaked API keys, tokens, and credentials from AI assistant chat histories and shell command logs
- 04Integrate security scanning into AI coding workflows via slash commands in Claude Code, Cursor, or Gemini CLI
- 05Run security gates in CI/CD pipelines with severity-based failure thresholds and SARIF output for GitHub Security
- 06Audit MCP server configurations for tool poisoning, schema injection, and unsafe permission grants
Related Agents
View morehermes-agent
The agent that grows with you
agency-agents
A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy injectors to reality checkers. Each agent is a specialized expert with personality, processes, and proven deliverables.
openinterpreter
A coding agent for open models like Kimi K3
cline
Autonomous coding agent as an SDK, IDE extension, or CLI assistant.
medusa — FAQ
What is MEDUSA and what does it scan for?+
MEDUSA is an AI-first security scanner agent with 40,000+ detection patterns that scans for AI/ML vulnerabilities (prompt injection, MCP poisoning, RAG attacks), traditional code security issues (SQLi, XSS, command injection), and supply chain attacks in AI editor configurations. It works immediately after installation with no external tool dependencies required.
How do I install MEDUSA?+
Install via pip with `pip install medusa-security`, then run `medusa scan .` to perform your first scan. For AI assistant integration, run `medusa init --ide all` to generate slash commands and context files for Claude Code, Cursor, Gemini CLI, and others.
Which AI coding assistants does MEDUSA work with?+
MEDUSA integrates natively with Claude Code, Cursor, Gemini CLI, GitHub Copilot, and OpenAI Codex. It generates slash commands like `/medusa-scan` and context files (CLAUDE.md, GEMINI.md, .claude/agents/) that enable these assistants to trigger security scans directly.
Does MEDUSA require API keys or external tools?+
No API keys are required. MEDUSA's 40,000+ built-in rules work immediately without external dependencies. It can optionally auto-detect and use external linters (bandit, eslint, shellcheck) if already installed, but they are not required.
Is MEDUSA free to use?+
Yes, MEDUSA is free and open source under AGPL-3.0 license. A commercial 'Professional' tier with runtime proxy filters for production LLM protection is planned at $99/dev/month.
How do I scan a remote GitHub repository for AI supply chain attacks?+
Use `medusa scan --git https://github.com/org/repo` or the shorthand `medusa scan --git org/repo`. MEDUSA will clone the repo and scan for weaponized AI editor configs, MCP poisoning, and other supply chain attacks across 28+ file types before you interact with it.
How do I install medusa?+
Open the source repository on GitHub and follow its README. medusa is a agent — MCP Agents Market links you directly to the official repo.
Is medusa free?+
medusa is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.