
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@guardbee/mcp-agent-graph-auditor
Advanced tools
MCP server that builds a reachability graph across multi-agent orchestration configs (LangGraph, CrewAI, AutoGen/ag2) to find transitive excessive agency — an agent with no dangerous tool of its own that can still reach one through delegation or group mem
🇬🇧 English | 🇹🇷 Türkçe
An MCP (Model Context Protocol) server that builds a reachability graph across a multi-agent orchestration and finds transitive excessive agency — an agent that was never directly given a dangerous tool, but can still reach one through another agent it's allowed to delegate to.
mcp-server-auditor catches an MCP server whose own tool grants shell/eval/SQL access directly. ai-code-scanner catches a single agent's tool list containing execute_command. Both of those are one hop: agent → tool. Multi-agent frameworks add a second kind of edge — delegation, group chat, function-execution routing — and a "safe-looking" agent with only a web_search tool can become dangerous the moment it's allowed to hand work off to a coworker that holds a shell tool. That two-hop path is invisible to a scanner that only looks at one agent's own tool list at a time.
This package sends usage telemetry by default (tool name + short parameters, scanned source is never included — see
@guardbee/mcp-telemetry). Disable withGUARDBEE_TELEMETRY=0.
Claude ──► agent-graph-auditor ──► Your multi-agent Python source
│
├─ LangGraph (add_node/add_edge — structural, read directly from the graph API)
├─ CrewAI (Agent/tools/allow_delegation + Crew membership — heuristic)
└─ AutoGen/ag2 (GroupChat membership, code_execution_config, register_function — heuristic)
has_tool (an agent's own toolset), delegates_to (CrewAI allow_delegation, LangGraph add_edge), group_member (AutoGen GroupChat co-membership — any member's output can be routed to any other by the manager), executes_via (AutoGen register_function's caller/executor split).ai-code-scanner's excessive-agency pattern uses, just applied to a graph of tools instead of one server's tool list.has_tool edge is a direct finding (still reported — useful even without a second agent in the picture). A capability tool reached only after crossing at least one delegates_to/group_member/executes_via edge is transitive — the finding this package exists for — and is always reported as critical, regardless of the tool's own base severity, because the agent holding it was never audited for it directly.LangGraph is the most reliable target: add_node/add_edge calls are the orchestration graph in the source, no inference needed. CrewAI and AutoGen require inferring delegation from framework semantics (allow_delegation, GroupChat membership) rather than an explicit edge in the code, so treat those as heuristic — see Limitations below.
guardbee.yml{
"mcpServers": {
"guardbee-agent-graph-auditor": {
"command": "npx",
"args": ["-y", "@guardbee/mcp-agent-graph-auditor"]
}
}
}
npx @guardbee/mcp-agent-graph-auditor scan ./agents --fail-on=high --format=sarif > results.sarif
| Tool | Description |
|---|---|
scan_text | Scans a Python snippet |
scan_file | Scans a single .py file |
scan_directory | Recursively scans a directory of .py files |
list_patterns | Lists the dangerous-capability catalog by category |
researcher = Agent(role="Researcher", tools=[web_search_tool], allow_delegation=True)
ops = Agent(role="Ops Engineer", tools=[shell_tool], allow_delegation=False)
writer = Agent(role="Writer", tools=[], allow_delegation=False)
crew = Crew(agents=[researcher, ops, writer], tasks=[])
researcher never holds shell_tool — but allow_delegation=True plus co-membership in the same Crew as ops means it can hand work off to an agent that does. This scanner reports:
🔴 CRITICAL Transitive excessive agency: reaches shell_tool
Path: Researcher → Ops Engineer → shell_tool
🔴 CRITICAL Direct excessive agency: reaches shell_tool
Path: Ops Engineer → shell_tool
writer — no tools, no delegation — gets no finding at all.
guardbee.yml)agent-graph-auditor:
fail-on: high # any | critical | high | medium | none
max-files: 2000
exclude:
- ".test.py"
Crew(agents=[researcher, ops]) call will only connect to Agent(...) definitions found in the same file, even when scanning a whole directory.ai-code-scanner's pattern-window matching makes), and it doesn't track reassignment, conditional agent construction, or dynamically built tool lists.speaker_selection_method isn't modeled — GroupChat co-membership is always treated as a bidirectional reachability edge, which is the conservative (over-inclusive, not under-inclusive) assumption.search_tool that secretly shells out internally won't be flagged; a tool named shell_tool_disabled will be. Review findings; don't take them as ground truth.npm run build
npm test # 31 unit tests
MIT — GuardBee
FAQs
MCP server that builds a reachability graph across multi-agent orchestration configs (LangGraph, CrewAI, AutoGen/ag2) to find transitive excessive agency — an agent with no dangerous tool of its own that can still reach one through delegation or group mem
We found that @guardbee/mcp-agent-graph-auditor demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.