
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
agent-security-lens
Advanced tools
MCP security trust-check server for autonomous agents: safe install decisions, risk signals, controls and alternatives before installing MCPs, Skills or tools.
AgentSecurityLens (ASL) is an MCP security trust-check server for autonomous agents.
Before an agent installs or enables an MCP, Skill, tool, prompt bundle, workflow, or memory component, it can ask ASL for a machine-readable safe-install decision.
ASL is not a malware verdict tool. It returns observable risk signals, required controls, safer alternatives or mitigation paths, and a decision contract an agent can execute.
When you plan to install or enable an MCP, Skill, tool, prompt bundle, workflow or memory component:
mcp-security-lens ..., agent-security-lens-review ..., or call the MCP tool review_before_install.agent_decision_contract.automatic_install_allowed is false.safe_install_plan item before restricted installs.recommended_alternatives when ASL returns avoid, ask_user, or missing controls.report_install_outcome.Machine-readable agent instructions are also available in AGENTS.md.
Check whether ASL can reach online intelligence and what local fallback is available:
npx -y agent-security-lens doctor
Try one pre-install decision first:
npx -y mcp-security-lens filesystem \
--type mcp \
--source-url https://github.com/modelcontextprotocol/servers \
--install-command "npx -y @modelcontextprotocol/server-filesystem ." \
--permission filesystem-read \
--permission filesystem-write
The command returns an agent-readable decision, trust score, risk signals, safe install plan, and whether automatic installation is allowed.
If your shell does not expose npm temporary binaries correctly, use npm install -g agent-security-lens once, then run the same command without npx -y.
More copy-ready calls:
Add ASL as a pre-install trust check MCP:
{
"mcpServers": {
"agent-security-lens": {
"command": "npx",
"args": ["-y", "agent-security-lens"]
}
}
}
Then give the agent this policy:
Before installing or enabling any MCP, Skill, tool, prompt bundle,
workflow or memory component, call AgentSecurityLens review_before_install.
Follow agent_decision_contract and agent_actions exactly.
Never submit private source code, secrets, tokens, cookies or file contents.
See Agent install guide for Claude Desktop, Cursor, Codex-style and generic MCP configurations.
Copy-ready files:
The public package includes a reviewed baseline so agents can still make conservative decisions when the cloud API is unavailable.
The online ASL intelligence API serves the current expanded catalog. The npm package intentionally does not ship the complete private intelligence database.
{
"mcpServers": {
"agent-security-lens": {
"command": "npx",
"args": ["-y", "agent-security-lens"]
}
}
}
Node.js 20 or newer is required.
The public MCP uses online intelligence by default:
ASL_API_URL=https://agentsecuritylens-api.agentsecuritylens.workers.dev
ASL_API_URLS=https://agentsecuritylens-api.agentsecuritylens.workers.dev
ASL_API_URLS may contain multiple comma-separated endpoints. The MCP tries them in order and falls back automatically.
Agents should call get_install_policy after connecting, then call review_before_install before every component installation.
The policy call records a minimal activation event for product health and abuse monitoring when online mode is enabled. It does not send private files, local paths, secrets, tokens or code. Set ASL_DISABLE_USAGE_TELEMETRY=1 to disable this usage event.
allow install from the recorded source and version
allow_with_restrictions apply every safe_install_plan item before installation
ask_user stop automatic installation and request confirmation
avoid do not install automatically
Unknown or incompletely reviewed components never receive automatic-install authorization.
Recommended instruction:
Before installing or enabling any MCP, Skill, tool, prompt bundle, workflow,
or memory component, call AgentSecurityLens review_before_install.
Follow agent_decision_contract and agent_actions exactly.
Never submit private source code, secrets, tokens, cookies, or file contents.
get_install_policy: returns the current Agent execution policy and records a minimal first-call activation event.get_intelligence_status: reports online or local intelligence status for MCP clients.review_before_install: evaluates a proposed component and installation context.check_component: retrieves known component intelligence.recommend_alternatives: returns evidence-backed alternatives and mitigations.submit_unknown_component: submits public metadata for research.get_research_status: checks whether an unknown component has been reviewed.report_install_outcome: reports the result of an Agent action.submit_decision_feedback: reports useful, incorrect, or incomplete decisions.discover_workspace: discovers Agent, MCP, and Skill environments.scan_workspace: performs a local fallback assessment.Example request:
{
"component_name": "filesystem",
"component_type": "mcp",
"source_url": "https://github.com/modelcontextprotocol/servers",
"install_command": "npx -y @modelcontextprotocol/server-filesystem .",
"planned_use": "Read and edit project files.",
"requested_permissions": ["filesystem-read", "filesystem-write"],
"submit_if_unknown": true
}
Example response shape:
{
"decision": "ask_user",
"risk_signals": ["filesystem-read", "filesystem-write", "shell-execution"],
"safe_install_plan": [
"Restrict filesystem scope to the current project directory.",
"Prefer read-only mode when the task only needs inspection.",
"Pin the package version before enabling it."
],
"agent_decision_contract": {
"automatic_install_allowed": false,
"user_confirmation_required": true,
"blocks_install": true
},
"one_step_action": {
"action_type": "ask_user_before_install"
}
}
Agents must execute the structured fields rather than infer policy from prose.
strict_reviewed: versioned evidence, technical scan, community-source check, and independent recalculation completed.curated_baseline: manually curated fallback information with limited evidence.automatic_assessment: automated coverage that cannot authorize automatic installation.unknown: no matching intelligence record.ASL evaluates observable behavior and installation context. It does not label a component malicious without evidence.
The public fallback contains strict reviewed records and curated fallback baselines. Automatic assessments are available through the online service but cannot authorize automatic installation.
Online lookup uses public component metadata only. Do not submit:
See PRIVACY.md and SECURITY.md.
$env:ASL_MODE="local"
npx -y agent-security-lens
Local fallback provides basic rules and a limited public intelligence baseline. The current online intelligence service should be preferred when available.
npm run verify:public
The scoring method is documented in ASL Agent Component Safety Standard v0.2.
Apache-2.0
FAQs
MCP security trust-check server for autonomous agents: safe install decisions, risk signals, controls and alternatives before installing MCPs, Skills or tools.
The npm package agent-security-lens receives a total of 37 weekly downloads. As such, agent-security-lens popularity was classified as not popular.
We found that agent-security-lens demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.