Skip to main content

Scanner Kinds

vet endpoint scan runs two independent scanners, each covering a different class of signals.

Item Types

Each discovered item is classified as one of the following types:

Scopes

What Gets Scanned

MCP Server Config Files

MCP server entries are read from JSON config files at well-known paths for each supported application.
System scopeProject scope
System scopeProject scope
System scope only
System scope
System scopeProject scope

Project Config Files

Project-level instruction and rules files are reported as project_config items.

CLI Tools

AI CLI binaries are discovered by searching $PATH for known names. Each candidate is executed with a version flag and its output is matched against a known pattern to confirm it is the expected tool.

IDE Extensions

Extension manifests are read from the following directories for each supported IDE distribution. Entries are matched against a curated list of known AI extension identifiers. Extension directories scanned:
Recognized AI extensions:

Agent Skills

The agent-skill scanner checks for skill subdirectories inside well-known paths for each supported agent. Every subdirectory found is reported as one agent_skill item.
Resolved relative to the user home directory (~/).
Resolved relative to the project directory.

MCP Server Details

For each discovered MCP server, the following fields are captured:

Endpoint Hub

What Endpoint Hub covers across your fleet.

Inventory

Discover AI tooling on each endpoint.

Package Guard

Track package installs across endpoints.

AI Tools Discovery

Find AI agents and MCP servers in use.