Scanner Kinds
vet endpoint scan runs two independent scanners, each covering a different class of signals.
Item Types
Each discovered item is classified as one of the following types:Scopes
What Gets Scanned
MCP Server Config Files
MCP server entries are read from JSON config files at well-known paths for each supported application.Claude Code
Claude Code
System scope
Project scope
Cursor
Cursor
System scope
Project scope
Windsurf
Windsurf
System scope only
Antigravity / Google Gemini CLI
Antigravity / Google Gemini CLI
System scope
VS Code
VS Code
System scope
Project scope
Project Config Files
Project-level instruction and rules files are reported asproject_config items.
CLI Tools
AI CLI binaries are discovered by searching$PATH for known names. Each candidate is executed
with a version flag and its output is matched against a known pattern to confirm it is the expected tool.
IDE Extensions
Extension manifests are read from the following directories for each supported IDE distribution. Entries are matched against a curated list of known AI extension identifiers. Extension directories scanned:Agent Skills
Theagent-skill scanner checks for skill subdirectories inside well-known paths for
each supported agent. Every subdirectory found is reported as one agent_skill item.
System-scope skill paths
System-scope skill paths
Resolved relative to the user home directory (
~/).Project-scope skill paths
Project-scope skill paths
Resolved relative to the project directory.
MCP Server Details
For each discovered MCP server, the following fields are captured:Endpoint Hub
What Endpoint Hub covers across your fleet.
Inventory
Discover AI tooling on each endpoint.
Package Guard
Track package installs across endpoints.
AI Tools Discovery
Find AI agents and MCP servers in use.

