Skip to main content

New: Malicious MCP server caught in the wild!

/ AGENTMESH /

The trust layer for the agentic supply chain.

Scan skills, MCP servers, and extensions before they touch your agents.

Know what your agents install before they install it.

AgentMesh continuously discovers, tracks, and scans AI agent skills, MCP servers, and VS Code extensions for prompt injection and supply-chain threats, and gives every one a verdict you can act on.

One catalog for the agentic supply chain

VS Code extensions

Browse and scan VS Code extensions for security threats, prompt injection, and supply-chain risks.

Agent skills

Browse and scan AI agent skills for prompt injection, malicious behavior, and supply-chain risks.

MCP servers

Browse and scan MCP servers for prompt injection, malicious behavior, and supply-chain risks.

Built for your security workflow

Clear verdicts

Every item is marked dangerous, risky, or clean, with the scan findings behind the call.

Look up by hash

Match an artifact by its SHA-256 across every version AgentMesh has seen, even after the latest one was rebuilt.

REST API

Query skills, extensions, and scan results programmatically and wire the verdicts into your own tooling.