medusa
The first AI-powered security scanner, supporting various AI/ML applications and code repository scans.
- Type
- Agent Skill
- Open source
- Yes
- GitHub Stars
- ★ 1.0k
- Source
- skill-github
- Repository
- github.com/Pantheon-Security/medusa
Overview
Medusa is a full-stack security scanner focused on AI, featuring over 40,000 detection patterns. It can identify vulnerabilities in AI/ML applications, LLM agents, MCP servers, and more. Easy to use with just `pip install`, requiring no additional tools. Medusa supports scanning GitHub repositories for AI supply chain attacks and detects leaked API keys. Suitable for developers, security teams, and AI project maintainers.
Capabilities
- ▪Scan GitHub repositories for AI supply chain attacks
- ▪Detect leaked API keys
- ▪Support detection of keys from 21 different vendor types
- ▪Identify malicious configurations in 28+ file types
- ▪Multi-core parallel processing for faster scanning
- ▪Support multiple report formats (JSON, HTML, Markdown, SARIF)
Use cases
Setup
pip install medusa-security
This information was compiled by AI from public sources and may contain inaccuracies — please refer to the source.
FAQ
Medusa supports which platforms?
Supports Windows, macOS, and Linux.
How do I get started with Medusa?
After installation, run `medusa scan --git <URL>` or `medusa secrets scan` directly.
Related skills
AI-Product-Development-Toolkit
AI-powered product planning and development toolkit featuring guided planning prompts, a Next.js app starter, and agent configuration.
sast-skills
Transform your AI coding assistant into a SAST scanner to automatically detect vulnerabilities in code.
Lightswind-UI-Library
AI-native CLI-first React component library with MCP Server support.
scientific-agent-skills
Transform any AI agent into a scientific assistant with 147 ready-to-use research skills.
susi_alexa_skill
A skill that enables question-and-answer interactions between Alexa and Susi AI.
claude-context
Provides code search capabilities for Claude Code, turning the entire codebase into context.