What gets scanned
Review the files most likely to change prompts, tools, hooks, and runtime behaviour.
- Agent skills and instruction packs
- Hooks and automation scripts
- MCP configuration files
- Plugin manifests and repo instructions
Public GitHub repository scanning
AAF Cloud Scan reviews public GitHub repositories for risky agent artifacts, hooks, MCP configs, plugin files, scripts, and repo instructions before you install, merge, or adopt them.
Queue a scan, open a report, and review verdicts, findings, and downloadable outputs in one place.
What it checks
Focused coverage for the files that shape agent behaviour, tool access, and workflow automation.
Review the files most likely to change prompts, tools, hooks, and runtime behaviour.
A fast path from repository URL to a report your team can review immediately.
Narrow scope, predictable controls, and a report-first workflow designed for trust.
Why this exists
Modern agent tooling often ships critical behaviour outside traditional application code. AAF Cloud Scan helps developers, security engineers, and technical founders inspect those files before install, merge, or adoption.
Understand the overall outcome quickly, with severity and supporting context at a glance.
Review structured findings without digging through raw logs or piecing together workflow output.
Export JSON and Markdown for security review, internal sharing, or audit records.