- Home
- Skills
- Security & Compliance
- ZeroDay Scanner
Works with the AI tools you already use
ZeroDay Scanner
Read-only Windows scan for supply-chain worms and AI-assistant persistence that antivirus misses — with wiper-safe cleanup.
Secure checkout via Stripe
See it in action
You say
Scan my Windows machine for supply-chain worms and hijacked AI-assistant configs, then show me anything suspicious: powershell -ExecutionPolicy Bypass -File .\scripts\scan.ps1
Your agent does
Result: 2 FLAG(S) | Check | Status | Detail | | py-startup | PASS | No sitecustomize/usercustomize startup hooks | | compromised-pkgs | FLAG | PyPI 'rlask' found in requirements.txt (known typosquat) | | ai-config | PASS | Claude/Cursor/VS Code hooks unchanged, no exfil patterns | | mcp | PASS | 52 MCP server defs across 14 configs, all known/clean | | skill-integrity | FLAG | Hidden Unicode (prompt-injection vector) in skill 'foo' | | persistence | PASS | Run keys, Startup, tasks, services match baseline |
Report: reports\scan-20260710-1421.md (exit code 1)
What you get
About this skill
ZeroDay is a read-only Windows scanner that hunts the new wave of supply-chain and AI-assistant attacks traditional antivirus misses: self-propagating npm/PyPI worms (Shai-Hulud, Miasma/TeamPCP class), malicious Python startup hooks (.pth / sitecustomize), hijacked AI coding-assistant configs (Claude, Cursor, VS Code — hooks, tasks.json, MCP servers), tampered agent skills/plugins, prompt-injection via invisible Unicode, credential-exfil GitHub repos, and stealth persistence (Run keys, Startup, scheduled tasks, services).
It runs 11 checks against a baseline you capture once, writes a clear markdown report plus a live self-refreshing status dashboard, and never modifies your system while scanning. When you confirm a threat, a separate, wiper-safe cleanup tool (quarantine.ps1) preserves a forensic copy first, then optionally neutralizes it (reversible) or removes it — and a plain-English REMOVAL.md walks you through the correct isolate-first order that avoids triggering a worm's file-wiper retaliation.
ZeroDay improves itself over time. Supply-chain campaigns churn constantly, so its detection signatures live in an updatable feed (signatures.json), not buried in code. A built-in research-and-merge workflow finds threats disclosed since your last update, verifies each indicator against authoritative advisories (GitHub Advisory Database, OSV / OpenSSF malicious-packages, npm/PyPI, Socket, Microsoft, StepSecurity), and merges only high-confidence, low-false-positive indicators — new worm packages, dropper filenames, exfil hosts, and repo-name patterns — via update-signatures.ps1, which validates and de-duplicates every entry so a bad signature can never flag everything. The scanner unions these with built-in fallbacks and reminds you when signatures go stale, so coverage keeps growing without ever touching the tool's logic.
No install, no dependencies beyond PowerShell, no admin required, and no data leaves your machine. Every release is sealed with a SHA-256 integrity manifest (verify-integrity.ps1) so you can confirm the download is untampered before you trust it.
How to install
Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- One-time purchase, yours forever