medusa
MCP ServerPantheon-Security/medusa
Medusa is an AI-first security scanner featuring over 40,000 detection patterns to identify vulnerabilities in AI/ML applications, LLM agents, and codebases. It includes specialized capabilities for detecting repository poisoning, analyzing remote GitHub repositories, and scanning chat or shell histories for leaked API keys.
Overview
Designed as a zero-setup security utility, Medusa allows developers to scan local directories or remote Git repositories instantly without configuring external analysis tools. Its comprehensive feature set encompasses detection for hundreds of CVEs, supply-chain vulnerabilities, poisoned AI assistant configuration files (such as Cursor and Claude Code configs), and exposed credentials across 21 different issuers. Furthermore, the tool provides robust mitigation features including interactive secret purging with byte-identical backup protections, multi-core parallel processing, and exportable reports in various standard formats.
Capabilities
- ▸AI supply chain and repository poisoning detection across 28+ file types
- ▸Secret and credential scanning in local files, shell history, and AI chat logs with interactive redaction
- ▸Detection of over 200 CVEs including Log4Shell, LangChain RCE, and MCP-Remote RCE
- ▸Native security rule evaluations for Rust and PHP
- ▸Multi-core parallel scanning with smart content-hash caching
- ▸Exporting reports to JSON, HTML, Markdown, and SARIF formats
Best for
Scanning local codebases or remote GitHub repositories for AI supply-chain attacks and vulnerabilities., Auditing AI coding assistant chat histories and shell history files for leaked API keys and sensitive credentials., Detecting weaponized or poisoned AI editor configurations (such as .cursorrules, .clinerules, and Claude Code settings)., Uncovering known CVEs in software projects across multiple programming languages like Python, Rust, and PHP.
Works with
実タスクにどれだけ役立つか(機能の豊富さ・用途の明確さ)。 — AIによるcapabilities/use-cases解析
実装・指示の品質。 — AIによるSKILL.md/README解析
リポジトリがどれだけ活発に保守されているか。 — GitHub 最終push日時の新しさ
ドキュメントの充実度・分かりやすさ。 — README/独自要約の情報量
危険・不審な挙動が無いか。 — AIによるセキュリティレビュー
ありふれたラッパーではない独自性。 — AIによる独自性判定
コミュニティの採用度。 — GitHub Stars/Forks(対数スケール)
対応AIエージェントの広さ。 — AIによる対応エージェント判定
ライセンス不明/制限あり(Red)のSkillは総合スコアに0.85倍の補正を適用します。 ランキングはこのScoreのみで決まり、広告で変わりません。 算出方法の詳細 →
Security considerations
Medusa operates entirely locally with no telemetry or remote data transmission. Secret purge operations create byte-identical backups prior to modification, and reports are stored securely with restricted file permissions.
Categories
Summary and analysis are original content generated by AI Skills Rank. The skill's source text is not reproduced here — view it on the linked repository.