medusa — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by Pantheon-Security · MCP Server · ★ 962

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is medusa safe to install? View the security audit →

About medusa

🐍 MEDUSA - AI Security Scanner AI-first security scanner with 40,000+ detection patterns for AI/ML, agents, and LLM applications. 🤖 Works out of the box - no tool installation required. 🚨 200 CVEs: Log4Shell, Spring4Shell, XZ Utils, LangChain RCE, MCP-Remote RCE, React2Shell 🔥 — Scan any repo for AI supply chain attacks (repo poisoning, prompt injection, MCP tool poisoning) 🔐 — Find leaked API keys in your Claude / Cursor / Copilot / shell

agent-securityai-securitycode-analysiscve-detectiondevsecopsllm-securitymcpnextjsopen-sourcepython

Quick Facts

Stars962
Forks153
LanguagePython
CategoryMCP Server
LicenseAGPL-3.0
Quality Score68.0746868959104/100
Open Issues2
Last Updated2026-08-10
Created2025-11-15
Platformsclaude-code, mcp, python
Est. Tokens~22k

medusa alternative? Top 6 similar tools

Looking for a medusa alternative? If you're comparing medusa with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • agent-audit by HeadyZhang · ⭐ 229

    Static security scanner for LLM agents — prompt injection, MCP config auditing, taint analysis. 51 rules mappe

  • node9-proxy by node9-ai · ⭐ 216

    IAM for your AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, revi

  • agentic-radar by splx-ai · ⭐ 1.1k

    A security scanner for your LLM agentic workflows

  • CyberStrike by CyberStrikeus · ⭐ 1.9k

    Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,

  • cyber-neo by Hainrixz · ⭐ 235

    Open-source cybersecurity analysis agent for Claude Code. Scans projects for vulnerabilities across all OWASP

  • pipelock by luckyPipewrench · ⭐ 896

    Firewall for AI agents. DLP scanning, SSRF protection, bidirectional MCP scanning, tool poisoning detection, a

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is medusa?

medusa is AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an always-on AI attack-signature scanner and native Rust . It is categorized as a MCP Server with 962 GitHub stars.

What programming language is medusa written in?

medusa is primarily written in Python. It covers topics such as agent-security, ai-security, code-analysis.

How do I install or use medusa?

You can find installation instructions and usage details in the medusa GitHub repository at github.com/Pantheon-Security/medusa. The project has 962 stars and 153 forks, indicating an active community.

What license does medusa use?

medusa is released under the AGPL-3.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to medusa?

The top alternatives to medusa on Agent Skills Hub include agent-audit, node9-proxy, agentic-radar. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools