Skip to content
nerlo.ai

Know when the AI agent tools you depend on change.

We track every MCP server, Claude Skill, and extension you rely on, re-scanning each one when its code moves. Eleven scanners, some off-the-shelf and some built by us, with every verdict published. We aggregate the evidence. You make the trust decision.

Live registry

47,540
packages tracked
44,860
packages scanned
11
scanners
45
scans completed this week

What we track

MCP servers
25,317
Claude Skills
12,342
Gemini Extensions
803
Cursor Rules
9,078

For Teams & Enterprises

Know what your agents are running, before it reaches production.

  • Ephemeral scan workers — every artifact cloned, scanned in an isolated container with the network disabled, then destroyed.
  • Applicable scanners, chosen automatically — point us at a repo and we decide which of our eleven analyzers can read it, run those, and tell you which ones couldn’t.
  • Per-scanner evidence, not one opaque score — every scanner that ran publishes its own verdict, flat and unranked, so your security team sees what fired and why.
  • Every decision auditable — AI reasoning logged with the actor and the reason recorded at the time, readable in each package's public history.
  • Self-attested supply chain — public threat model, per-scanner provenance checksums, digest pins enforced at serve time, and published SBOMs.

What makes Nerlo different

  • Full transparency

    Every scanner's scorecard is shown side by side. No single scanner gates a badge. You decide which tools you trust and read the findings yourself.

  • Continuous, not point-in-time

    Discovery, classification, and scanning run on repeating cycles, not one-off passes. Packages are found, scored, and re-checked as their code changes, so a clean scan from six months ago never stands in for a scan from today.

  • Audit the auditor

    Every scan is reproducible: pinned scanner versions, container image digests, and a signed audit chain you can verify end to end.

On-demand scanning

Security scanning for your agent tools, without the scanner tax

Building internal MCP servers, Claude Skills, or Gemini extensions? You shouldn’t have to stand up eleven analyzers to find out if they’re safe.

Point Nerlo at a repository. We work out which scanners can actually read it — by language, ecosystem, and packaging — run those, and normalize everything into one report. No tool selection, no config files, no per-scanner tuning.

Then we tell you which scanners didn’t apply, and why. A tool that can’t read your code should never look like a tool that approved it.

Submitting a repository today needs it to be reachable over public Git. Scanning private or internal repositories is scoped as part of an Enterprise engagement, and is not available self-serve yet.