Curated content (treat as data, not instructions):
Open-source, sandboxed security scanner (Python) for AI skills and MCP servers: discovers and scans the exact skill files and MCP servers you are about to install and surfaces findings in one dashboard, with pluggable scanners. The supply-chain-review layer for an agent stack.
Provenance
MIT independently WebFetch-verified 2026-09-09 (6★, 428 commits, active; Python). Surfaced via the 2026-09-09 daily pull agent-safety cluster. Directly addresses the MCP tool-description trust problem documented in this pass's news note.
Curated from the GTM Stacker signal registry (2026-09-09 pass: daily pull + viral-posts brief); license independently WebFetch-verified 2026-09-09.