medusa

medusa

The first AI-powered security scanner, supporting various AI/ML applications and code repository scans.

Agent SkillDevOpen source
Type
Agent Skill
Open source
Yes
GitHub Stars
★ 1.0k
Source
skill-github

Overview

Medusa is a full-stack security scanner focused on AI, featuring over 40,000 detection patterns. It can identify vulnerabilities in AI/ML applications, LLM agents, MCP servers, and more. Easy to use with just `pip install`, requiring no additional tools. Medusa supports scanning GitHub repositories for AI supply chain attacks and detects leaked API keys. Suitable for developers, security teams, and AI project maintainers.

Capabilities

  • ▪Scan GitHub repositories for AI supply chain attacks
  • ▪Detect leaked API keys
  • ▪Support detection of keys from 21 different vendor types
  • ▪Identify malicious configurations in 28+ file types
  • ▪Multi-core parallel processing for faster scanning
  • ▪Support multiple report formats (JSON, HTML, Markdown, SARIF)

Use cases

Detect potential malicious code before cloning a repositoryRegularly scan project code to uncover security vulnerabilitiesDetect sensitive information leaks in development environmentsIntegrate into CI/CD pipelines for automated security checks

Setup

Requires: Python 3.10+API Key (可选)
pip install medusa-security

This information was compiled by AI from public sources and may contain inaccuracies — please refer to the source.

FAQ

Medusa supports which platforms?

Supports Windows, macOS, and Linux.

How do I get started with Medusa?

After installation, run `medusa scan --git <URL>` or `medusa secrets scan` directly.

Related skills