# Tripwire

> Updated 2026-09-09 · type: tool · category: mcp-agents · status: active · rev 1

Tripwire is an open-source sandboxed scanner that reviews AI skills and MCP servers for safety before you install them.

- Open source: yes (MIT)
- Self-hostable: yes
- Pricing model: free
- Best for: Teams installing third-party Claude skills and MCP servers who want to vet them before granting access.
- Last verified: 2026-09-09

- **Canonical:** https://gtmstacker.com/registry/tool/tripwire-agent-scanner/
- **Source:** [github · neomatrix369/tripwire](https://github.com/neomatrix369/tripwire)
- **Tags:** mcp-agents, agent-security, mcp, supply-chain, governance, self-hostable
- **Repository:** https://github.com/neomatrix369/tripwire

## Is Tripwire open source?

Yes, Tripwire is open source under the MIT license.

## How much does Tripwire cost?

Tripwire is free to use.

## Can I self-host Tripwire?

Yes, Tripwire can be self-hosted (the source is available under the MIT license).

## Alternatives & related

- [Geiger](https://gtmstacker.com/registry/tool/geiger/)
- [MagicVault](https://gtmstacker.com/registry/tool/magicvault/)


---

Open-source, sandboxed security scanner (Python) for AI skills and MCP servers: discovers and scans the exact skill files and MCP servers you are about to install and surfaces findings in one dashboard, with pluggable scanners. The supply-chain-review layer for an agent stack.

## Provenance

- MIT independently WebFetch-verified 2026-09-09 (6★, 428 commits, active; Python). Surfaced via the 2026-09-09 daily pull agent-safety cluster. Directly addresses the MCP tool-description trust problem documented in this pass's news note.
- Curated from the GTM Stacker signal registry (2026-09-09 pass: daily pull + viral-posts brief); license independently WebFetch-verified 2026-09-09.
