Skip to content

Add Lurkr static scanner#42

Open
oleg-bk wants to merge 1 commit into
ProjectRecon:mainfrom
oleg-bk:codex-add-lurkr-ai-agent-security
Open

Add Lurkr static scanner#42
oleg-bk wants to merge 1 commit into
ProjectRecon:mainfrom
oleg-bk:codex-add-lurkr-ai-agent-security

Conversation

@oleg-bk
Copy link
Copy Markdown

@oleg-bk oleg-bk commented May 25, 2026

Adds Lurkr to the Static Analysis & Linters section.\n\nLurkr is an MIT-licensed, local-only static scanner for AI-agent and MCP repositories. It focuses on pre-runtime capability-surface checks: declared-vs-implemented tool mismatch, shell tools without approval metadata, external MCP endpoints, credential flows into LLM calls, and related agent workflow hygiene.\n\nWhy this fits the list:\n- open-source and maintained;\n- directly scoped to autonomous-agent security;\n- runs locally without executing project code or sending telemetry;\n- complements existing runtime gateways and red-team tools by checking repository capability surfaces before deployment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant