vulnex/VASO Security Scan

Scan AI agent installations and MCP server configurations for security issues

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
versionGit ref to install from github:vulnex/vaso (tag like v0.4.2, branch, or commit SHA).nov0.4.12
agentScan a single agent only (openclaw, nanoclaw, picoclaw, ironclaw, nanobot, zeroclaw, nemoclaw, hermes, claude-code, codex). Omit to scan all detected agents.no""
formatOutput format: terminal, json, sarif, markdown, or html.nosarif
outputPath for the scan report. Defaults to vaso-results.<format-extension>.no""
fail-onExit non-zero when findings reach this severity: critical (default), warning, info, or none.nocritical
working-directoryDirectory to run vaso from. Defaults to the workspace root.no.
upload-sarifWhen format is sarif, also upload the report to GitHub Code Scanning. Defaults to true.notrue
debugEnable --debug to print full stack traces on errors.nofalse
extra-argsAdditional CLI flags appended verbatim to vaso scan (escape hatch for flags this action does not model).no""
namedescription
report-pathAbsolute path to the generated scan report.