
Security scanner for AI agents GitHub repos.
No transaction required
Trusted by developers building the next generation of intelligent, decentralized software.
Three steps. Thirty seconds. Complete security report.
Enter any public GitHub repository URL. We support any language, framework, or stack.
ScanMyBot fetches your code and runs 30+ security checks across 5 categories in real-time.
Receive a 0-10 health score, prioritized issues, severity ratings, and actionable fix recommendations.
From secrets to smart contracts — everything your AI agent and Web3 project needs.
AWS keys, OpenAI tokens, Ethereum private keys, committed .env files
Vulnerable packages, outdated versions, known CVEs in your stack
.gitignore validation, environment variable checks, deployment settings
Input sanitization, template usage, delimiter separation, system prompt protection
eval() detection, SQL parameterization, XSS prevention, command injection checks
Input length limits, rate limiting, request timeouts, token usage monitoring
Reentrancy protection, access control, unchecked calls, integer overflow
No hardcoded keys, limited approvals, transaction simulation, slippage protection
Oracle manipulation, flash loan protection, MEV risks, transaction deadlines
Deep analysis across every category — from secrets to smart contracts.
AWS keys, API tokens, private keys, committed .env files. Smart filtering eliminates false positives.
Vulnerable packages, outdated versions, known CVEs. Checks package.json across your entire repo tree.
Full OWASP LLM Top 10 coverage: prompt injection, insecure output, training data poisoning, excessive agency, and more.
Smart contract reentrancy, unlimited token approvals, oracle manipulation, flash loan protection, MEV risk analysis.
Everything you need to know about ScanMyBot.
Paste a GitHub URL, get a full security report in seconds. No signup required.