Skip to main content
Glama

Project Shield

한국어

Security scanner for AI coders and MCP users. It checks projects and AI-agent configuration for exposed secrets, PII, insecure MCP settings, prompt injection, and risky Claude Code hooks.

npm version

Run the free scan

npx project-shield scan ./my-project

Project Shield v2.0.0 runs locally and includes security grading, fix guidance, and AI-agent environment auditing.

Related MCP server: agent-audit

Free and Pro

Feature

Free

Pro

Project scans

5/month

50/month

Environment audits

3/month

20/month

Fix-it guidance

Top 3 summaries

All guides with code and references

Badge

Watermarked

Clean badge with UUID and verification URL

Evidence Pack

Not included

JSON + PDF with integrity seal

PII findings

Count only

File and line details

Project Shield Pro is $29/month and is delivered through an automated Polar license-key benefit.

The Polar checkout displays Clouvel, the publisher account for Project Shield. Taxes, when applicable, are calculated by Polar from the buyer's billing address and shown before payment.

Commands

# Scan a project
npx project-shield scan ./my-project

# Audit the local AI coding environment
npx project-shield audit

# Activate a Polar-issued Pro license
project-shield activate PSH-XXXX-XXXX-XXXX-XXXX

# Check license status
project-shield status

What Pro unlocks

  • Full fix-it guides with code examples and references

  • JSON and PDF Evidence Packs

  • Clean badges with UUID and verification URL

  • Full Claude Code environment checks and hooks analysis

  • Higher monthly scan and audit limits

Security notes

  • Run scans only on projects you own or are authorized to inspect.

  • Review findings before changing code or configuration.

  • Never paste secrets or customer data into public issues.

License

MIT

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    Scans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.
    19
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Security scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.
    8 npm
    2
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Scans MCP servers for prompt-injection, tool-poisoning, and SSRF vulnerabilities using 30+ canonical rules across 5 severity tiers, with optional signed safety reports for procurement.
    5
    MIT