Universal preflight security scanner for AI coding agents — Detects hooks injection, credential exfiltration & backdoors in .cursorrules, CLAUDE.md, AGENTS.md and more.
<p align="center">
<img src="docs/logo.png" alt="DeepSafe Scan" width="180">
</p>
<h1 align="center">DeepSafe Scan</h1>
<p align="center">
<strong>AI Agent 环境通用安全预检扫描器</strong>
</p>
<p align="center">
<a href="https://python.org"><img src="https://img.shields.io/badge/python-3.9%2B-blue.svg" alt="Python"></a>
<a href="#零依赖"><img src="https://img.shields.io/badge/依赖-零-green.svg" alt="零依赖"></a>
<a href="https://clawhub.ai"><img src="https://img.shields.io/badge/ClawHub-deepsafe--scan-orange.svg" alt="ClawHub"></a>
<a href="https://xiaoyiweio.github.io/deepsafe-scan/"><img src="https://img.shields.io/badge/在线文档-GitHub%20Pages-blue?logo=github" alt="GitHub Pages"></a>
</p>
<p align="center">
<a href="https://xiaoyiweio.github.io/deepsafe-scan/">
<strong>📖 完整文档与演示 → xiaoyiweio.github.io/deepsafe-scan</strong>
</a>
</p>
<p align="center">
<em>运行前先扫描。一条命令,保护你的 AI Agent 环境免受密钥泄露、提示词注入、Hooks 后门攻击。</em>
</p>
<p align="center">
想了解这些攻击是怎么运作的?→ <a href="https://github.com/XiaoYiWeio/ai-agent-attack-techniques"><strong>AI Agent Attack Techniques</strong></a>
</p>
---
<p align="center">
<strong>⚡ 攻击者只需 3 秒,就能从你的 AI Agent 环境中窃走 SSH Key、API Key 和全部敏感凭证。</strong><br>
<sub>↓ 真实攻击演示(3 倍加速) · <a href="https://xiaoyiweio.github.io/deepsafe-scan/#demo">观看完整原速视频 →</a></sub>
</p>
<p align="center">
<img src="docs/demo.gif" alt="3秒窃取你的全部凭证 - DeepSafe Scan 攻击演示" width="800">
</p>
<p align="center">
<sub>你 clone 的下一个仓库,可能已经在等你打开它了。</sub>
</p>
---
<p align="center">
<strong>支持平台:</strong>
<img src="docs/openclaw.svg" alt="OpenClaw" width="48" valign="middle"> <strong>OpenClaw</strong>
<img src="docs/claudecode-color.svg" alt="Claude Code" width="40" valign="middle"> <strong>Claude Code</strong>
<img src="docs/cursor.svg" alt="Cursor" width="40" valign="middle"> <strong>Cursor</strong>
<img src="docs/codex-colAgent that generates comprehensive documentation, API references, architecture diagrams, and developer onboarding guides from existing code.
Agent configuration for systematic bug investigation that traces issues from error logs through the codebase to root cause with suggested fixes.
Agent for integrating third-party APIs including SDK setup, type generation, error handling, retry logic, and rate limit management.
Cursor's built-in autonomous coding agent that can make multi-file edits, run terminal commands, search the codebase, and iteratively build features with minimal human intervention.
Cloud-based autonomous coding agent that runs in the background on remote sandboxed environments, handling complex multi-step tasks while you continue working.
Cursor's multi-file editing agent within Composer mode that can create, edit, and delete files across your entire project in a single conversation.