agent-threat-rule/ATR Scan

Scan MCP configs and SKILL.md files for AI agent security threats using Agent Threat Rules (ATR)

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 13, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: agent-threat-rule/agent-threat-rules@dc9e58e2b3e6dafc9ecf731be63220196ac2d54c # v3.5.8

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
pathPath to scan (file or directory)no.
severityMinimum severity to report (informational, low, medium, high, critical)nomedium
fail-on-findingFail the action if threats are foundnotrue
sarif-filePath to write SARIF output filenoatr-results.sarif
upload-sarifUpload SARIF to GitHub Security tabnotrue
namedescription
threat-countNumber of threats found
sarif-filePath to the SARIF output file