Malware drafted the AI CLIs already installed
A compromised npm package ran the developer's own Claude, Gemini and Q command-line tools and asked them to hunt for secrets and wallets.
Security for teams of AI agents
Your engineers run Claude Code, Codex, Cursor and more on one laptop, all sharing the same files. Sherlock finds what those agents can do as a group: the cheapest attack, step by step, or a certificate that none exists.
See it work · 36 seconds
A support bot written in LangGraph. Sherlock reads the graph, writes the safety question as a formula, and a SAT solver answers it. Toggle the fixes, or let it play.
Press play for a one-minute walkthrough, or toggle the fixes yourself.
Computed live in your browser by the same checker as above, from the LangGraph code exported with export(app). Cost = agents an attacker must hack + times you must click Allow.
On watch
Each agent is reviewed alone. Sherlock checks how they move together.
Scan your Mac
Three steps, about a minute. The script copies its findings to your clipboard, and this page checks them in your browser. Nothing is uploaded.
One command. It runs scan.py, a 1511-line Python script with no dependencies. It finds every AI agent it can on your Mac and reads the approval settings of 15 of them: Claude Code (per project, with every approval you saved), Codex, GitHub Copilot in VS Code and its CLI, Gemini CLI, Cline, Aider, Continue, OpenCode, Goose, Zed, Kiro, Amazon Q, Devin and their MCP servers. Agents whose settings it cannot read are modeled as unrestricted, and checks whether folders like ~/.ssh exist. It never opens a secret.
curl -fsSL https://raw.githubusercontent.com/Ning0Luo/sherlock/main/scan.py | python3 -
Open Terminal, paste and press Return. When it prints “Copied”, the results are on your clipboard. It only says that when the scan worked.
On Linux there is no clipboard tool, so it prints the results instead: add > scan.json to the end and choose the file in step 3.
Certified
Scanners and red-team tools can only say they found nothing. Sherlock proves it. Every rule it passes comes with a certificate: evidence that no attack exists within your budget, which you can check yourself without trusting Sherlock.
A certificate covers the permissions Sherlock read and the attacker it models: someone who writes web pages, hacks up to the agents in your budget and gets up to that many prompts approved. The command-line tool also writes SAT-solver proofs, checked by an independent proof checker.
Works with LangGraph
Sherlock reads a compiled LangGraph graph without running it: its nodes, the tools each one can call, the state they share, which nodes read which keys, and which tools wait for a person to approve.
Read automatically, without running the app: nodes, ToolNodes and subgraphs; tools called from plain node code; input_schema; interrupt_before and interrupt() as your approval; the app's input as attacker-written; and the long-term Store. Unknown tools are assumed to do anything.
Mark what you trust on the node itself: metadata={"sherlock": {"trusted": True, "strips": ["attacker"]}}.
Scales with SAT: proves a 128-agent app safe in about a second, where trying every combination gives up past 20.
Watch Sherlock check a LangGraph app, with the formula and the solver's work shown step by step: see the demo at the top of the page ↑
Why now
An ordinary program does what its code says. An AI agent may follow instructions hidden in a web page, an issue or a README. Take over one honest agent with text, and the files it shares lead to the rest.
A compromised npm package ran the developer's own Claude, Gemini and Q command-line tools and asked them to hunt for secrets and wallets.
A prompt injection could make Cursor's agent write its own MCP config file, which then ran attacker commands. Control files bridge agents.
An agent with access to public and private repos read a malicious issue and copied private data into a public pull request.
How it works
Each rule says how many hacked agents and Allow clicks it must survive.
The scanner reads the permission settings of every agent on the machine. Structure only, never secret values, and nothing leaves the machine.
Rules and rights compile to SAT. A solution is a concrete attack, replayed by a simulator. No solution comes with a certificate that a separate checker verifies.
Each failure names the fewest hacked agents and approvals an attacker needs. Change one setting, re-run in two seconds, and watch the cost rise.
First results
Pilot program
Run Sherlock across your developer fleet: one policy file, a scan on every laptop, and a CI gate that blocks a new agent or plugin when it opens a path to your secrets.
Ning Luo · University of Illinois Urbana-Champaign