Browse
→ Infrastructure
→ frostagent
frostagent
Deny-by-default capability linter for AI agent tool setups. It reads MCP servers, hooks, permission rules, skills, and local server source across Claude Code, Claude Desktop, Cursor, VS Code, Codex, Zed, Windsurf, Gemini CLI, OpenCode, and Cline, then probes stdio, HTTP, or SSE tools and fails policies for unapproved capabilities, plaintext secrets, unpinned packages, dangerous permissions, or changed tool schemas. Public GitHub repository created September 5, 2026.
MCP unverified
Integration
| Transport | stdio |
| Auth | none |
| Endpoint | frostagent probe --user |
| Install | git clone https://github.com/keithadler/frostagent.git |
Use Cases
| 01 | Audit local AI-agent configurations for unapproved MCP capabilities, hooks, skills, and permission rules |
| 02 | Detect plaintext secrets, unpinned packages, remote HTTP servers, risky containers, and destructive commands in agent tool configs |
| 03 | Pin tool descriptions and schemas so MCP tool drift fails a build before agents trust changed capabilities |
Tags
security capability-policy mcp-audit tool-schemas permissions secrets lockfile agent-safety
Machine-readable: /api/servers.json
· JSON-LD schema embedded in <head>