AI supply-chain security scanner
Scan your AI artifacts for security risks — free, no account required.
Paste a GitHub, GitLab, or Bitbucket repo URL (public or private) or upload a folder. Jiffy reads every skill, MCP config, .cursorrules, agents.md, and prompt template, then flags credential exfil, backdoors, prompt injection, and risky tool permissions.
- Finds credential exfil, backdoors, prompt injection, over-privileged MCPs
- Reads skills, MCP configs, Cursor/Windsurf rules, agents.md, Copilot instructions
- Static analysis — your artifacts are read, never executed
- Free for public repos. Under 30 seconds.
Try:
We never store your repo contents past 24 hours for anonymous scans. Sign up to save scans and unlock full findings, file evidence, and SARIF export.
Coming soonScan your repo
The live threat feed is on its way
We’re wiring these numbers and this feed up to real scan results from public marketplaces and repos. Scanning your own repo or folder works today — give it a run.
