AI-first security scanner with 9,600+ detection rules for AI/ML, LLM agents, and MCP servers.
medusa is easy to set up with strong trust signals. Check agent compatibility and use-case fit before adding it to your workflow.
gh repo view Pantheon-Security/medusa --webOpen the official repository or website.
Check the README for package manager, auth, and platform requirements.
Try it in a small test task inside your agent workflow.
Repository setup guidance
Strong trust signals; still review the README and permissions before production use.
Last commit was about 105 days ago.
594 GitHub stars indicate community interest.
4 open issues signal maintenance load.
AGPL-3.0 license detected.
0 security/trust notes recorded.
Setup difficulty is 1/5.
A terminal dashboard to monitor AI coding agents like Claude Code and Codex CLI in real-time.
AI agent security scanner that detects vulnerabilities in agent configurations, MCP servers, and tool permissions.
A full-stack AI Red Teaming platform for securing AI ecosystems with comprehensive scanning and evaluation.
A bridge between Streamable HTTP and stdio MCP transports, enabling flexible MCP server connectivity.
Medusa is a security scanner that finds vulnerabilities in code, especially for AI and machine learning projects. It can scan any GitHub repository for issues like leaked secrets, poisoned AI configurations, and known CVEs. You can use it right after installing with pip, no extra tools needed.
Medusa is an AI-first security scanner developed by Pantheon Security. It features over 9,600 detection patterns covering AI/ML applications, LLM agents, MCP servers, RAG pipelines, and traditional code. Key capabilities include: scanning any GitHub repo for AI supply chain attacks (repo poisoning, prompt injection, MCP tool poisoning) using `medusa scan --git <URL>`; finding leaked API keys in Claude/Cursor/Copilot/shell history with `medusa secrets scan` and interactive redaction; detecting 200+ CVEs (Log4Shell, Spring4Shell, XZ Utils, LangChain RCE, React2Shell); parallel multi-core processing (10-40x faster); beautiful CLI with progress bars; IDE integration (Claude Code, Cursor, VS Code, Gemini CLI); smart caching for fast rescans; configurable via .medusa.yml; cross-platform (Windows, macOS, Linux); multiple report formats (JSON, HTML, Markdown, SARIF). The tool is designed for zero setup—works immediately after `pip install medusa-security`. It is licensed under AGPL-3.0 and has received 594 stars on GitHub.
594
Stars
108
Forks
4
Issues
AGPL-3.0
License
AI-first security scanner with 9,600+ detection rules for AI/ML, LLM agents, and MCP servers.
Security engineers focusing on AI/ML application security, DevOps and DevSecOps professionals integrating security into pipelines, AI/ML developers building LLM agents or MCP servers
The setup section provides repository-level starting guidance, not a guarantee of an independently verified installation. Check the official README and release notes.
Review repository permissions, executed commands, data sent to external services, and dependencies before use.
Similar or complementary options to evaluate include abtop, agentshield, AI-Infra-Guard.
Aug 20, 2026