Discovery and registry
Find the agents before you govern them
You cannot write a policy for something nobody has told you exists.
The problem
Agents arrive the way scripts always have: one engineer, one afternoon, one API key that still works six months later. By the time anyone asks what is running, the answer lives in four repositories and somebody’s laptop.
Four kinds of thing, four ways of finding them
Each one is found differently, and each one is a different sort of blind spot when it is missing.
agentfox check .Model clients and agent frameworks in committed code, with the file and line.
agentfox quickscan .Local coding-assistant session state — the agent someone is using today that was never committed.
agentfox scan mcpRecorded with a digest, which is the only thing that makes a later change detectable.
included in the repo scanInstructions the model will follow, read for planted directives and shell fences.
- 01
Read the code without running it
Point it at a repository and it reports every model client, tool call and agent framework it can find, with the file and line. Static analysis, so a scan costs nothing and cannot have side effects.
agentfox check . - 02
Find what is actually running
Committed code is a poor proxy for live behaviour. Local coding-assistant session state is a second signal, and it catches the agent somebody is using today that was never committed anywhere.
agentfox quickscan . - 03
Snapshot the tool servers
Every MCP server’s tools are recorded with a digest, which is what makes a later change detectable. Hygiene problems in the descriptions are raised at the same time.
agentfox scan mcp - 04
Read the skills, including the parts nobody proofreads
A skill file is instructions the model will follow. They are parsed for planted directives and shell fences — and frontmatter that will not parse is reported and kept, not silently discarded, because discarding it is how a poisoned skill scans clean.
- 05
Attach an owner, or raise a finding
Every agent in the registry has a state — active, quarantined or killed — and an owner. An agent with no owner is a reportable finding rather than a row in a table, because the first question after an incident is who operates this.
agentfox agents discover
What discovery does not do
It reads repositories and local session state. It does not sweep employee laptops through an EDR or MDM, so an agent on a machine nobody points it at stays invisible — that is a distribution gap, not a detection one. Static analysis also cannot see an agent assembled at runtime from configuration it has never been shown.
Try to break it before you trust it
No account, no install, and the same enforcement code as the product.
pip install agentfox agentfox init && agentfox demo
Offline: no API key, no downloaded weights, no network egress.