Skip to main content
H

Husk

Husk is a local-first security scanner that protects developer machines and AI agents by auditing dependencies, secrets, developer configuration, AI-agent configuration, and MCP servers. It installs without elevated privileges, supports offline scanning, and integrates with AI coding agents through MCP for continuous monitoring. The scanner checks package names and versions against public advisory databases without sending source files or local paths.

Stockholm, Sweden · HQ
210+ followers
  • Artificial Intelligence
  • AI Agents
  • Cybersecurity
  • Developer Tools
  • Software Only
Updated 1 month ago

Funding

Funding rounds are not available yet.

Founders

Founder details are not available yet.

Product

Problem

Developer machines and AI agents are increasingly targeted through vulnerable dependencies, exposed secrets, and misconfigured agent or MCP server settings. Traditional security tools often require cloud uploads, elevated privileges, or manual configuration, creating friction and privacy concerns for developers and automated workflows.

Solution

Husk provides a local-first security scanner that audits dependencies, secrets, developer configuration, AI-agent configuration, and MCP servers directly on the user's machine. The tool installs without sudo or shell startup file changes, and it can run offline or online, sending only package names and versions to public advisory databases while keeping source files, local paths, and secrets local. Husk integrates with AI coding agents via MCP, enabling agents to run scans, self-check their configuration, and receive security findings without leaving their workflow. It supports one-time scans, scheduled recurring scans, and continuous daemon monitoring, with results delivered through the agent's native interface or operating-system schedulers.

Target Audience

Primary users are individual developers, development teams, and AI-agent operators who need to secure their local development environments and automated coding workflows without compromising privacy or requiring cloud-based tooling.

Features

  • Scans dependencies, secrets, developer configuration, AI-agent configuration, and MCP servers in a single pass
  • Local-first architecture that never uploads source files, local paths, or secrets; online mode only sends package names and versions to public advisory databases
  • MCP integration for AI coding agents, including installation, self-check, and configuration preview with `--dry-run`
  • Offline scan mode for environments where external lookups are not permitted
  • Recurring protection via weekly or monthly scheduled scans or continuous daemon monitoring using cron, systemd user timers, or launchd
  • Reviewable installation protocol that downloads, inspects, and executes the installer without elevated privileges or shell startup file modifications
This profile is AI-generated and may contain inaccuracies.