DeepSweep: AI Agent Security & Code Review

中文说明 ↓
Your AI coding agent can already run shell commands, reach your database, write to your repo, and call tools over MCP. Right now, in this workspace. Do you know everything it can reach?
DeepSweep reviews the environment your agents run in and the code they write, locally in your editor. It maps what each agent can reach (MCP servers, shell, repository write, databases, hooks), finds credentials written in plain text into agent configs, and flags the security problems AI assistants introduce the moment they land. It reports what it finds and offers fixes. Your source code stays on your machine.
This extension is the free, local first step. Run one command, DeepSweep: Review My Agent Environment. In under a second, the agent environment review shows which of your agents' settings let them act without asking you: run any shell command, push, deploy or publish, reach beyond the project (the whole disk, your home folder, no sandbox), or start MCP servers that are not pinned to a version or reach a remote server with no sign-in. It also finds credentials written in plain text into agent configs. No account needed, and your code stays on your machine. As you type, it also checks the code your AI assistant writes against 77 patterns, with zero configuration. Works with Antigravity, Trae, Devin Desktop, GitHub Copilot, Claude Code and OpenAI Codex. Cursor: install from the VSIX (deepsweep.ai/install/cursor).
What this extension does not do. It does not sit between an agent and its tools, so it cannot stop a tool call before it runs. It shows what your agents can do, catches risky changes as they are written, and offers a fix with an undo for each one it applies.
Start with one command, DeepSweep: Review My Agent Environment. In under a second, the agent environment review lists what each agent can reach and each setting that lets it act without asking you, and what to change. A settings file it cannot read is named, never counted as safe. Free and local, with no account and no upload of your code.
And because it all runs on your machine, DeepSweep catches what your AI agent got wrong first, privately, in your editor, before it ever reaches a pull request, a CI pipeline, or your security team's dashboard. Local-first means the review is your private safety net. Fix what you find quietly and ship clean.
What your agents may do without asking
Agent settings decide whether an agent asks you first. One line can turn that off for every command. The review reads Claude Code's settings (project, local and user), OpenAI Codex's ~/.codex/config.toml, the profile files beside it (in CODEX_HOME when you set it) and a project's .codex/config.toml, Gemini CLI's settings (project and user), VS Code's agent-mode settings and every MCP config it finds, and shows:
- [WITHOUT ASKING]
bypassPermissions, Bash or Bash(*) in the allow list, allow rules for git push, terraform apply, npm publish and similar, enableAllProjectMcpServers, a hook that answers "allow" for every tool, Codex approval_policy = "never" (in your config or in a profile, which the review names), VS Code chat.tools.autoApprove, and MCP servers marked trust: true.
- [BEYOND THE PROJECT] Extra directories or a filesystem MCP server covering the whole disk or your home folder, and Codex
sandbox_mode = "danger-full-access".
- [MCP SERVERS] Packages and images on
@latest, :latest, a version range or no version at all, so the code can change between starts, and remote servers with no sign-in set.
Each one says what to change, and the setting is marked in the Problems panel. When a setting that acts without asking or reaches beyond the project appears after a review you already had, the once-a-day change notice names it, the same way it names a new MCP server. For bypassPermissions, a Bash or git push-style rule in the allow list, Codex approval_policy = "never", VS Code chat.tools.autoApprove and Gemini trust: true, the review can apply the safer setting for you: you see the exact change first, and one click undoes it, with your first 2 fixes free on a free account. A rule you also put in ask or deny is left alone. A settings file DeepSweep cannot read is named, and the review does not count it as safe. The shell row reflects these settings: it reads higher when an agent may run commands without asking and lower when your settings limit them.
Secrets in your agent configs
Agent setup guides tell you to paste a token straight into an MCP config: a GitHub token in ~/.cursor/mcp.json, an API key in ~/.claude.json, a Bearer header on a remote server. Any agent or extension that can read that file can read the token.
The review checks the agent configs in your workspace and in your home folder, including ~/.cursor/mcp.json, ~/.claude.json (its per-project servers too) and .vscode/mcp.json. It looks in env values, request headers, server URLs and command-line arguments, and recognises GitHub, OpenAI, Anthropic, Slack, AWS, Google, Stripe and other token formats. Each one is listed with its file, server and key, and the ones in your home folder are marked in the Problems panel. DeepSweep shows where each credential is and never its value. References such as ${input:token} or ${env:GITHUB_TOKEN} are how this is done safely, and they are left alone.
Review My Agent Environment
AI coding agents quietly accumulate capabilities you never explicitly granted. MCP servers with broad tool access, shell execution, database reach, repository write, deploy hooks. DeepSweep: Review My Agent Environment maps them in a single local pass:
- [CAPABILITIES] Detects what the agent can actually do: MCP tool access, shell execution, database access, repository write, deploy. It reads agent settings and MCP configs in your workspace and your home folder, including Claude Code's settings,
~/.codex/config.toml and .vscode/settings.json. Metadata only. No source ever leaves the editor.
- [IDENTITY] Derives a deterministic local agent identity, so the review is stable and reproducible from one run to the next.
- [GAPS] Shows where an agent can act without asking you: a setting that runs any shell command or skips approval, a push, deploy or publish rule, access beyond the project, and MCP servers that are not pinned or have no sign-in. Each finding says what to change. It advises rather than blocks.
The agent environment review runs fully on-device in under a second. No account, no cloud, no upload. Free.
The Review is the free first step toward agent authorization: knowing which agent can do what, and where it can act beyond what you intended. Local-first and at no cost.
Protect Claude Code
If you use Claude Code, DeepSweep: Protect Claude Code (also a button on the review) adds deny and ask rules to Claude Code's own permission settings. Claude Code checks those rules before it runs a tool.
- [DENY] Claude Code is then blocked from opening
.env and .env.* files, and .pem and .key files (Keynote presentations included), anywhere on your computer, SSH keys named id_* in ~/.ssh, and the AWS, GitHub CLI, npm and .netrc credential files in your home folder. A rule that blocks reading a file also blocks editing it.
- [ASK] Edits to bash, zsh and fish startup files, anything in
~/.ssh, Dockerfiles, GitHub Actions workflows, git hooks, and Claude Code's own settings and MCP lists.
- [ASK]
npm, pnpm, yarn or bun add and install, any pip command, uv add, uv pip, poetry add, cargo add and cargo install, go get and go install, and gem install.
- [ASK]
rm -rf, rm -r, git reset --hard, git clean, sudo and git push.
- [ASK] Every tool of each MCP server set up for this folder, or for you in Claude Code's settings, when you run the command.
You pick all your projects or just this one (offered in a folder you trust), and you see the exact change before anything is written. For just this one, the rules go where Claude Code keeps your personal settings for the repository (its top folder, or the main checkout when you work in a worktree), and a file DeepSweep creates there is kept out of your commits. Your other settings are kept as they are, and a settings file DeepSweep cannot read cleanly is left untouched. DeepSweep: Undo Claude Code Protection takes the rules back out.
What the rules are not: they match file paths and how a command starts. They do not read file contents, and a command written another way (a different option order, a script, a command run inside another program) can get past them. Other installers, and commands that download and run a package, are not covered. MCP servers from plugins, claude.ai connectors, servers set up only for other projects, and servers added later get no rule until you run the command again. The rules apply to Claude Code only.
Catch what AI assistants miss, as you type
Beyond the one-time environment review, DeepSweep watches every change your AI assistant makes and flags risk the moment it lands.
Traditional SAST tools (Snyk, SonarQube, Semgrep) check hand-written code against hand-written rules. They were not designed for what happens when an AI agent generates, pastes, or modifies code in your editor.
DeepSweep reads the agent's environment as well as the code it produced. As you type, it looks for the patterns of things AI assistants consistently get wrong: prompt injection in rules files, hallucinated dependencies, hardcoded secrets pasted from example code, MCP tool-access misconfigurations, and Unicode backdoors that look invisible to humans but execute faithfully at runtime. Each of these is a pattern match (not benchmarked).
- [VERIFY] Checks every save and keystroke (800 ms debounce). No CI wait.
- [LOCAL] Pattern matching runs entirely on your machine. Source never leaves the editor.
- [AGENTIC] AI-specific patterns with CVE references. They cover the
.cursorrules, mcp.json, and agent-config attack surface.
Quick Start
- Install. Search
DeepSweep in the Extensions view and click Install. In Cursor, where the extension index does not list us, use the one-minute package steps at deepsweep.ai/install/cursor instead.
- Review your agent. Run
DeepSweep: Review My Agent Environment from the Command Palette to see what your agent can reach and what it may do without asking you.
- Open a project. DeepSweep then checks AI-generated code automatically on open and on save.
- Fix findings. Click any finding for a one-line fix hint, or copy a remediation prompt and paste it back to your AI assistant.
Keyboard: Shift+Option+Cmd+E (macOS) / Shift+Alt+E (Windows/Linux) to check the current file.
What It Detects
| Category |
Examples |
Severity |
How it is checked |
| Agent Settings |
Agent may run any command, push, deploy or publish without asking; access beyond the project; unpinned MCP servers; remote MCP servers with no sign-in |
High |
Agent settings review |
| Rules File Backdoors |
Invisible Unicode, bidirectional text overrides, hidden instructions in .cursorrules |
Critical |
Pattern match (not benchmarked) |
| Prompt Injection |
Instruction override, role reassignment in agent-config files |
Critical |
Pattern match (not benchmarked) |
| Credential Exposure |
Hardcoded API keys, AWS secrets, Stripe keys, private keys |
Critical |
Pattern match (not benchmarked) |
| Data Exfiltration |
Code or secrets routed to external URLs via rules files |
Critical |
Pattern match (not benchmarked) |
| MCP Security |
Unrestricted tool access, remote server connections, missing sandboxing |
High |
Pattern match (not benchmarked) |
| Supply Chain |
Hallucinated packages, typosquatted dependencies, slopsquatting |
High |
Pattern match (not benchmarked) |
| Injection Flaws |
SQL injection, XSS, command injection, path traversal |
High |
Pattern match (not benchmarked) |
| Misconfigurations |
Insecure crypto, disabled TLS verification, debug mode in production |
Medium |
Pattern match (not benchmarked) |
77 patterns total, each a pattern match (not benchmarked). 37 are AI-specific and agentic-code-aware (prompt injection, MCP, rules-file, exfiltration, config). The other 40 are traditional security patterns.
Features
- Review My Agent Environment. One-command local review of your agent's capabilities, identity, and authorization gaps (no account, no cloud)
- Live Checks. Analyzes AI-generated code as you type, with an 800 ms debounce
- Certify-on-Write. Catches an AI agent the moment it writes a new critical/high finding, with one-click Revert / Auto-Fix
- Verification Proof. See exactly what was checked: patterns, files, categories, duration
- 9 UI Surfaces. Status bar, Problems panel, CodeLens, Quick Fix, tree view, webview, decorations, notifications, output channel
- AI Assistant Detection. Identifies which tool generated the code (Cursor, Copilot, Claude, Devin Desktop)
- Finding Suppression. Suppress with reason categories, expiration dates, and audit trails
- Fix All Auto-Correct. One-click static fixes across your workspace
- README Badge. Add a badge that shows your project's review record to your README in one click, after you see the exact change and with an undo, or copy the markdown instead
- Config File Monitoring. Auto-rechecks when
.cursorrules, .env, or mcp.json change
Pricing
|
Free |
Pro |
Team |
| Agent Environment Review |
Yes |
Yes |
Yes |
| Code checks |
Unlimited |
Unlimited |
Unlimited |
| Patterns |
77 |
77 |
77 |
| Fix hints |
Yes |
Yes |
Yes |
| Full fix prompts |
Yes (signed in) |
Yes |
Yes |
| Apply a fix |
2 included, then Pro |
Yes |
Yes |
| Finding suppression |
Session only |
Persistent |
Persistent + audit trail |
| README badge |
Basic |
Yes |
Yes |
| Fix All auto-correct |
Counts as one applied fix |
Yes |
Yes |
| Price |
$0 |
$19/mo |
$99/mo |
The Repo Grade, the AI Code Health Score, and the Agent Environment Review are free forever. A free signed-in account gets unlimited fix prompts and 2 applied fixes, enough to watch the grade move. Pro lifts the cap on applying fixes. The grade itself is never gated. All checks run locally. No code is sent to external servers for pattern matching.
About: Agent Authorization
Model alignment is a statistical promise. It is not a per-action proof. An aligned coding agent can still silently delete a permission check, paste a hardcoded credential, or write a .cursorrules file that hides instructions in invisible Unicode. It can also act on your shell, your database, and your repo while doing it.
DeepSweep answers the question alignment can't: which agent is authorized to do what, and where can it act beyond that? This extension answers it locally and for free, with a review of your agent's capabilities and authorization gaps. That turns "we hope it behaves" into "we know what it can reach."
This extension is the reference implementation. The full argument lives in the book:
The Authorized Agent: Identity, Authorization, and Audit for AI Agents in Production
Book One in the DeepSweep.ai Thesis series, by Brad McEvilly.
Requirements
- Any VS Code-compatible editor on 1.74.0 or newer: VS Code, Antigravity, Trae, Devin Desktop (formerly Windsurf), Kiro, VSCodium, code-server. Cursor: install from the VSIX (below).
- Node.js runtime (included with your editor)
Cursor: install from the VSIX. Cursor's extension index does not list DeepSweep, so searching the Extensions panel there will not find it. Download the package and add it from the panel's ... menu instead. It takes about a minute, no terminal: deepsweep.ai/install/cursor.
Every editor's current install path is at deepsweep.ai/install.
Commands
| Command |
Description |
DeepSweep: Review My Agent Environment |
Review your AI agent's capabilities, identity, and authorization gaps |
DeepSweep: Protect Claude Code |
Add Claude Code permission rules, after you see the exact change |
DeepSweep: Undo Claude Code Protection |
Take those rules back out |
DeepSweep: Apply the Safer Agent Setting |
Change one flagged agent setting to its safer value, after you see the exact change |
DeepSweep: Undo a Safer Agent Setting |
Put that settings file back exactly as it was |
DeepSweep: Review Project |
Check the entire workspace |
DeepSweep: Review Current File |
Check the active file |
DeepSweep: Copy Fix Prompt |
Copy remediation prompt for your AI assistant |
DeepSweep: Fix All (Auto-Correct) |
Apply all static fixes |
DeepSweep: Add Badge to README |
Add the badge to your README, after you see the exact change. Nothing is committed |
DeepSweep: Undo README Badge |
Take the badge back out, leaving the README exactly as it was |
DeepSweep: Copy README Badge |
Copy badge markdown for your README |
DeepSweep: Sign In with GitHub |
Enable fix hints and dependency checks |
Privacy
DeepSweep runs pattern matching and the agent-environment review locally in your editor. No source code is sent to external servers for analysis.
Usage data is on by default, and it tells us which features work. This is everything it contains:
- Your setup: your editor and its version, and whether it runs on the desktop, on the web or in a cloud workspace. The extension version, your operating system and its version, and CPU architecture. Your display language and region setting, time zone, and the size and pixel density of your screen and the size of the DeepSweep panel.
- What you use: the features, commands and DeepSweep settings you use and when you use them. When a session starts, ends, gains or loses focus, and how long it lasts. Your plan, and the steps of signing in, upgrading and checking out, including a referral code if you arrived through a referral link. For the README badge, whether you previewed, added or took back the badge, where you started from, whether DeepSweep created the README, and why it left a README alone, never the file, its contents or the project. For each of these, whether it was something you did or something DeepSweep did on its own.
- Review results: the grade and score, finding counts, and the IDs, categories and severities of the patterns that matched. The extensions of the files they were found in (such as
ts), and whether you applied a fix (for an agent setting, which kind of setting it was and whether you applied, declined or undid it, and at one, seven and thirty days whether that setting stayed as DeepSweep left it, never the file or its contents). What started the review, how long it took, and the AI coding assistant detected. For the agent-environment review, which kinds of access the agent has (MCP tools, shell, database, git write, deploy), how many capabilities and authorization gaps it found, its overall risk, its access verdict, how many of the agent's actions were ungoverned, unused or aligned, and the agent's lifecycle state. How many credentials the review found written in plain text in agent configs, how many agent config files it checked, could not read or skipped as too large (counts only), and whether Claude Code was detected. How many agent settings it found that let an agent act without asking, reach beyond the project or run an unpinned MCP server, how many of those settings DeepSweep can change for you and which kinds of setting they are, which assistants' settings files it found (never the files themselves), whether a copyable summary was offered, how many settings files it checked or could not read (counts only), and whether shell commands may run without asking, are limited, are left at the agent's default, or could not be determined.
- Your workspace, in outline: which of a few language families and package ecosystems it uses, and the file extensions it contains. How many folders it has, whether it is trusted, and whether it has a git repository, an MCP config or Cursor rules.
- Errors: the kind of error and where in DeepSweep it happened, down to the function and position in DeepSweep's own code, the length of its message, and a short one-way fingerprint that groups identical errors. Never the message itself, and never a path from your computer.
- Identifiers: an identifier your editor provides for this machine (or a random one when it provides none), and values derived from it, one of which changes every day. Your account identifier if you sign in. Not your email or username.
- Connection health: for each request DeepSweep makes to its own service, what it was for and whether it got an answer. That is starting a sign-in, the dependency check, refreshing your plan, linking this machine to your account, or registering the install. Roughly how long it took and how many tries it needed. For a request that failed, the step where it stopped: finding the server, connecting, securing the connection, or waiting for the answer. Never the address, the request or the answer.
- Location: our servers and our analytics provider receive your IP address with each request and estimate an approximate location from it.
Usage data never includes source code, file contents, file names or paths (only a file's extension, and, for an error, its position in DeepSweep's own code), folder or project names, the text of error messages, or credential values. Turn it off with the deepsweep.telemetry.enabled setting or with DEEPSWEEP_TELEMETRY=off below. In VS Code, DeepSweep also follows the editor's own telemetry setting. In other editors (Cursor, Antigravity, Trae, Devin Desktop, Kiro, VSCodium and the like) the editor's own telemetry switch is not read, so use the DeepSweep setting or DEEPSWEEP_TELEMETRY=off there.
When usage data cannot be sent, it is kept on this machine for up to 7 days, up to a fixed size, and sent once the connection works again. It holds only what would have been sent, and turning usage data off deletes it.
Requests that features make. These are not usage data, so the usage-data switches do not stop them. DEEPSWEEP_OFFLINE=1 stops every one of them.
- Dependency check (signed in): the names and versions of the registry packages your manifests declare, to check that each one exists. Local, git and URL dependencies are left out.
- README badge (when you copy or add one while signed in): your review's finding counts, the number of files reviewed, and an identifier derived one-way from the workspace location, so the badge can show your review record.
- Sign-in: the requests needed to sign you in, and a link between this machine's identifier and your account.
- Invite codes (when you ask for yours): a read of your account's status.
- Update check: a request to the extension registry for the latest version. Turn it off with the
deepsweep.checkForUpdates setting.
- Feedback: the message you write, and your email if you give it, with the extension version and your editor's name.
What DeepSweep connects to. Three places, and nothing else. Uninstalling DeepSweep opens nothing and sends nothing.
| Connects to |
When |
What is sent |
To turn it off |
us.i.posthog.com and api.deepsweep.ai |
While you use DeepSweep, in batches |
The usage data listed above |
deepsweep.telemetry.enabled set to false, DEEPSWEEP_TELEMETRY=off, or DEEPSWEEP_OFFLINE=1. In VS Code only, also the editor's own telemetry setting (other editors' switches are not read) |
api.deepsweep.ai |
The first time DeepSweep starts (and the next start, if that attempt failed) |
Your setup (editor, extension version, operating system, language, time zone), the machine identifier described above, and a referral code if you arrived through a referral link |
The same switches as usage data |
api.deepsweep.ai |
When you sign in, and regularly while you are signed in, to keep your plan current |
What signing in needs, and a link between this machine's identifier and your account |
Do not sign in, or DEEPSWEEP_OFFLINE=1 |
api.deepsweep.ai |
After a review, when you are signed in |
The names and versions of the registry packages your manifests declare |
Do not sign in, or DEEPSWEEP_OFFLINE=1 |
api.deepsweep.ai |
When you copy or add the README badge while signed in |
Finding counts, the number of files reviewed, and a one-way identifier for the workspace |
Do not copy or add the badge, or DEEPSWEEP_OFFLINE=1 |
api.deepsweep.ai |
When you look up your invite codes, and at most once a session while you are signed in, to find a checkout you left unfinished |
A read of your account's status |
DEEPSWEEP_OFFLINE=1 |
api.deepsweep.ai |
When you choose to upgrade while signed in |
The plan and billing period you chose, and which editor you started from |
Do not upgrade from the editor |
api.deepsweep.ai |
When you send feedback |
Your message, your email if you give it, the extension version and your editor's name |
Do not send feedback |
open-vsx.org or marketplace.visualstudio.com, whichever you installed from |
Shortly after DeepSweep starts, then every 12 hours |
A request for the latest version number |
deepsweep.checkForUpdates set to false, or DEEPSWEEP_OFFLINE=1 |
Every request to api.deepsweep.ai also carries the extension version, your editor's name, and your operating system and CPU architecture. Requests that need your account (your plan, the dependency check, the badge, invite codes and checkout) also carry your session.
Air-gapped? Set DEEPSWEEP_OFFLINE=1. With it set, DeepSweep originates no network requests of any kind. No telemetry, no dependency check, no sign-in, nothing. The review itself is unaffected: patterns, findings, diagnostics, code lenses, the grade and the fixes all run on your machine and always did. Offline mode turns off only what needs a network: the dependency check and signing in, which need a registry and an account service to answer, and with them publishing your badge's review record and the update notice.
Telemetry off-switch: set DEEPSWEEP_TELEMETRY=off before launching your editor and DeepSweep sends no telemetry at all. No analytics, no diagnostics, no telemetry network calls. For CI machines and corporate policy. Works in every supported editor.
Error reports never carry your file paths. When something goes wrong, DeepSweep records the kind of problem: a file it could not read, a request that timed out. It never records the message itself, so no folder name, project name or username reaches an error report.
Privacy Policy
Autonomous agent workspaces (Devin and similar)
DeepSweep also runs where no human is watching. In autonomous agent
environments such as Devin, add DeepSweep to the machine snapshot the same
way you'd install any editor extension. It activates with the workspace,
reviews the agent environment on open, and re-checks files as the agent writes
them, exactly as it does under a human's hands. The agent's workspace gets the
same review a developer's would, in the environment where the agent is
actually working, before its output ships.
It runs inside a Devin session with no special configuration beyond installing
the extension into the snapshot.
Human Security Audit
When a review surfaces something you want a second opinion on, or you want your agent setup checked before it ships, a DeepSweep human security audit goes deeper than any automated pass. A security engineer reviews your agent configuration, permissions, and toolchain against a fixed-scope checklist and delivers a written report with clear [PASS] / [WARN] / [FAIL] findings and the exact steps to fix each one.
Audits start at $99, and if we find no critical issues, it's free. Book directly from the review panel in your editor, or at deepsweep.ai/audit.
Links
This page is the body of two listings, so both are named here. One codebase, one release, two registries:
DeepSweep:AI 智能体安全与代码审查
English ↑
DeepSweep 在你的编辑器里本地审查 AI 编码智能体:看清每个智能体能访问什么,哪些设置让它无需询问即可行动(运行任意 shell 命令,推送、部署或发布,超出项目范围访问整个磁盘、你的主目录或不使用沙箱,启动未固定版本或未设置登录的远程 MCP 服务器),并找出以明文写进智能体配置的凭据。它报告发现并提供修复,不会拦截智能体对工具的调用。在你输入时,它还会用 77 条检测模式检查 AI 助手写出的代码,零配置。支持 Antigravity、Trae、Devin Desktop、GitHub Copilot、Claude Code 和 OpenAI Codex。Cursor:通过 VSIX 安装(deepsweep.ai/install/cursor)。
从一条命令开始——DeepSweep: Review My Agent Environment(审查我的智能体环境)。智能体环境审查在一秒内列出每个智能体能访问什么,以及每一条让它无需询问即可行动的设置,并给出修改方法。无法读取的设置文件会被点名,绝不会被当作安全。免费、本地运行、无需账号,也不会上传你的代码。
因为一切都在你的机器上运行,DeepSweep 会最先、私密地、在你的编辑器里发现 AI 智能体犯的错——早于 Pull Request、早于 CI 流水线、早于安全团队的仪表盘。本地优先意味着它是你的安全网,而不是你的"记录在案":安静地修好,第一次就干净地交付。
审查我的智能体环境(Review My Agent Environment)
AI 编码智能体会悄悄积累你从未明确授予的能力——拥有广泛工具访问权的 MCP 服务器、Shell 执行、数据库访问、仓库写入、部署钩子。DeepSweep: Review My Agent Environment 在一次本地遍历中把它们全部映射出来:
- 【能力】 通过读取工作区和主目录中的智能体设置与 MCP 配置(包括 Claude Code 的设置、
~/.codex/config.toml 和 .vscode/settings.json)检测智能体实际能做什么——MCP 工具访问、Shell 执行、数据库访问、仓库写入、部署。只读取元数据;源代码永远不会离开编辑器。
- 【身份】 派生确定性的本地智能体身份,使每次审查结果稳定、可复现。
- 【缺口】 标出智能体无需询问即可行动的地方:运行任意 shell 命令或跳过审批的设置、推送、部署或发布规则、超出项目范围的访问,以及未固定版本或未设置登录的 MCP 服务器。每项发现都给出修改方法。它提供建议,而不是强制拦截。
智能体环境审查完全在设备端运行,耗时不到一秒。无需账号、无需云端、无需上传。免费。
这份审查是迈向智能体授权的免费第一步——知道哪个智能体能做什么、它可能在哪里越权。本地优先、零成本。
智能体无需询问就能做什么
智能体设置决定它是否先询问你。一行设置就能对所有命令关闭询问。审查会读取 Claude Code 的设置(项目、本地和用户级)、OpenAI Codex 的 ~/.codex/config.toml、其旁边的配置文件(profile,设置了 CODEX_HOME 时从那里读取)和项目中的 .codex/config.toml、Gemini CLI 的设置(项目和用户级)、VS Code 的智能体模式设置以及它找到的每个 MCP 配置,并显示:
- [无需询问]
bypassPermissions、允许列表中的 Bash 或 Bash(*)、允许 git push、terraform apply、npm publish 等命令的规则、enableAllProjectMcpServers、对每个工具都回答“allow”的钩子、Codex 的 approval_policy = "never"(在主配置或某个 profile 中,审查会说明是哪个 profile)、VS Code 的 chat.tools.autoApprove,以及标记为 trust: true 的 MCP 服务器。
- [超出项目范围] 覆盖整个磁盘或你的主目录的额外目录或文件系统 MCP 服务器,以及 Codex 的
sandbox_mode = "danger-full-access"。
- [MCP 服务器] 使用
@latest、:latest、版本范围或未指定版本的软件包和镜像(每次启动时代码都可能不同),以及未设置登录的远程服务器。
每一项都给出修改方法,这些设置还会在“问题”面板中标出。如果在你已经做过审查之后又出现了这类设置,每天一次的变更提醒会像提醒新 MCP 服务器一样指出它。对于 bypassPermissions、允许列表中的 Bash 或 git push 一类规则、Codex 的 approval_policy = "never"、VS Code 的 chat.tools.autoApprove 和 Gemini 的 trust: true,审查可以替你应用更安全的设置:你会先看到确切的改动,一键即可撤销,免费账户的前 2 次修复免费。你同时放进 ask 或 deny 的规则不会被标记。DeepSweep 无法读取的设置文件会被点名,审查不会把它当作安全。shell 一行会反映这些设置:智能体可以无需询问运行命令时风险更高,你的设置限制了命令时风险更低。
智能体配置中的密钥
智能体的安装指南常常让你把令牌直接粘贴进 MCP 配置:~/.cursor/mcp.json 里的 GitHub 令牌、~/.claude.json 里的 API 密钥、远程服务器上的 Bearer 请求头。任何能读取该文件的智能体或扩展,都能读到这个令牌。
审查会检查工作区和你主目录中的智能体配置,包括 ~/.cursor/mcp.json、~/.claude.json(也包括其中各项目的服务器)和 .vscode/mcp.json。它会查看 env 值、请求头、服务器 URL 和命令行参数,并能识别 GitHub、OpenAI、Anthropic、Slack、AWS、Google、Stripe 等令牌格式。每一处都会列出所在文件、服务器和键名,主目录中的那些还会在“问题”面板中标出。DeepSweep 只显示凭据的位置,从不显示它的值。 ${input:token}、${env:GITHUB_TOKEN} 这样的引用才是安全的做法,不会被标记。
保护 Claude Code
如果你使用 Claude Code,DeepSweep: Protect Claude Code(审查结果中也有对应按钮)会把拒绝规则和询问规则写入 Claude Code 自己的权限设置。Claude Code 会在运行工具之前检查这些规则。
- [DENY] 之后 Claude Code 将无法打开你电脑上任何位置的
.env 和 .env.* 文件,以及 .pem 和 .key 文件(包括 Keynote 演示文稿),~/.ssh 中名为 id_* 的 SSH 密钥,以及主目录中 AWS、GitHub CLI、npm 和 .netrc 的凭据文件。禁止读取某个文件的规则也会禁止编辑它。
- [ASK] 修改 bash、zsh 和 fish 的启动文件、
~/.ssh 中的任何文件、Dockerfile、GitHub Actions 工作流、git hooks 以及 Claude Code 自己的设置和 MCP 列表;npm、pnpm、yarn 或 bun 的 add 和 install,任何 pip 命令,uv add、uv pip、poetry add、cargo add 和 cargo install、go get 和 go install,以及 gem install;rm -rf、rm -r、git reset --hard、git clean 和 sudo;git push;以及运行该命令时,在 Claude Code 设置中为当前文件夹或为你配置的每个 MCP 服务器的所有工具。
你可以选择应用到你的所有项目或仅当前项目(仅在你信任的文件夹中提供),并在写入之前看到确切的改动。选择仅当前项目时,规则会写入 Claude Code 为该仓库保存个人设置的位置(仓库的顶层文件夹;在 worktree 中工作时则是主检出目录),DeepSweep 在那里新建的文件不会进入你的提交。你的其他设置保持不变;DeepSweep 无法干净读取的设置文件不会被修改。DeepSweep: Undo Claude Code Protection 会把这些规则撤回。
这些规则的局限:它们匹配文件路径和命令的开头部分,不读取文件内容;换一种写法的命令(不同的参数顺序、脚本、在另一个程序中运行的命令)可以绕过它们。其他安装工具,以及下载并运行软件包的命令,不在覆盖范围内。来自插件的 MCP 服务器、claude.ai 连接器、只为其他项目配置的服务器,以及之后新增的服务器,在你再次运行该命令之前都没有规则。这些规则只对 Claude Code 生效。
在你打字的同时,捕获 AI 助手漏掉的问题
除了一次性的环境审查,DeepSweep 还会关注 AI 助手做出的每一次改动,在风险落地的那一刻立即标记。
传统 SAST 工具(Snyk、SonarQube、Semgrep)用手写规则检查手写代码。它们并不是为"AI 智能体在编辑器里生成、粘贴、修改代码"这一新场景设计的。
DeepSweep 读取智能体的运行环境,而不仅仅是它生成的代码。你打字时,它会查找 AI 助手持续犯错的那些问题的模式——规则文件中的提示注入、幻觉依赖、从示例代码粘贴进来的硬编码密钥、MCP 工具访问配置错误,以及人眼不可见、运行时却忠实执行的 Unicode 后门。以上每一项都是模式匹配(未经基准测试)。
- 【验证】 每次保存和输入都会检查(800 毫秒防抖)。无需等待 CI。
- 【本地】 模式匹配完全在你的机器上运行。源代码永远不会离开编辑器。
- 【智能体感知】 附带 CVE 参考的 AI 专属模式,专为
.cursorrules、mcp.json 和智能体配置这一攻击面而构建。
快速开始
- 安装 —— 在扩展视图中搜索
DeepSweep,点击 Install。在 Cursor 中,扩展索引尚未收录 DeepSweep,请改用 deepsweep.ai/install/cursor 上约一分钟的安装包步骤。
- 审查你的智能体 —— 在命令面板运行
DeepSweep: Review My Agent Environment,查看智能体的能力与授权缺口。
- 打开一个项目 —— DeepSweep 会在打开与保存时自动检查 AI 生成的代码。
- 修复发现 —— 点击任一发现即可获得一行修复提示,或复制修复提示词,粘贴回你的 AI 助手。
快捷键:Shift+Option+Cmd+E(macOS)/ Shift+Alt+E(Windows/Linux)检查当前文件。
检测范围
| 类别 |
示例 |
严重度 |
检查方式 |
| 智能体授权缺口 |
智能体可访问超出预期范围的 MCP 工具、Shell、数据库、仓库写入或部署 |
高 |
智能体设置审查 |
| 规则文件后门 |
不可见 Unicode、双向文本覆盖、.cursorrules 中的隐藏指令 |
严重 |
模式匹配(未经基准测试) |
| 提示注入 |
智能体配置文件中的指令覆盖、角色重新分配 |
严重 |
模式匹配(未经基准测试) |
| 凭据暴露 |
硬编码的 API 密钥、AWS 密钥、Stripe 密钥、私钥 |
严重 |
模式匹配(未经基准测试) |
| 数据外泄 |
通过规则文件把代码或密钥发送到外部 URL |
严重 |
模式匹配(未经基准测试) |
| MCP 安全 |
不受限的工具访问、远程服务器连接、缺失沙箱 |
高 |
模式匹配(未经基准测试) |
| 供应链 |
幻觉依赖包、拼写抢注依赖(typosquatting / slopsquatting) |
高 |
模式匹配(未经基准测试) |
| 注入缺陷 |
SQL 注入、XSS、命令注入、路径穿越 |
高 |
模式匹配(未经基准测试) |
| 错误配置 |
不安全加密、关闭 TLS 校验、生产环境开启调试模式 |
中 |
模式匹配(未经基准测试) |
共 77 条模式,均为模式匹配(未经基准测试)—— 37 条面向 AI 与智能体代码(提示注入、MCP、规则文件、外泄、配置),另有 40 条传统安全模式。
定价
|
Free |
Pro |
Team |
| 智能体环境审查 |
有 |
有 |
有 |
| 代码检查 |
无限 |
无限 |
无限 |
| 检测模式 |
77 |
77 |
77 |
| 修复提示 |
有 |
有 |
有 |
| 完整修复提示词 |
有(登录后) |
有 |
有 |
| 应用修复 |
含 2 次,之后需 Pro |
有 |
有 |
| 发现抑制 |
仅当前会话 |
持久化 |
持久化 + 审计记录 |
| README 徽章 |
基础 |
有 |
有 |
| 一键全部修复 |
计为 1 次已应用的修复 |
有 |
有 |
| 价格 |
$0 |
$19/月 |
$99/月 |
仓库评级(Repo Grade)、AI 代码健康分和智能体环境审查永久免费。免费登录后获取修复提示词的次数不设上限,并包含 2 次应用修复,足以让你看到评级提升;Pro 解除应用修复的次数限制。评级本身永远不受限制。所有检查都在本地运行——不会把代码发送到外部服务器做模式匹配。
隐私
DeepSweep 的模式匹配与智能体环境审查在你的编辑器内本地运行。不会把源代码发送到外部服务器进行分析。
使用数据默认开启,帮助我们了解哪些功能有用。以下是其全部内容:
- **你的环境:**你的编辑器及其版本,它运行在桌面、网页还是云端工作区,扩展版本,操作系统及其版本,CPU 架构,显示语言与地区设置,时区,以及屏幕尺寸与像素密度和 DeepSweep 面板的尺寸。
- **你的使用情况:**你使用的功能、命令和 DeepSweep 设置及其使用时间,会话何时开始、结束、获得或失去焦点以及持续多久,你的套餐,以及登录、升级和结账的各个步骤,如果你通过推荐链接而来,还包括推荐码。对于 README 徽章,还包括你是否预览、添加或撤销了徽章,从哪里开始,DeepSweep 是否创建了 README,以及它为何没有改动某个 README,从不包括文件、其内容或项目。以上每一项还包括它是你的操作还是 DeepSweep 自动执行。
- **审查结果:**评级与分数、发现数量、命中模式的 ID、类别与严重度、发现所在文件的扩展名(例如
ts)、你是否应用了修复(对于智能体设置,还包括设置的类型以及你是应用、拒绝还是撤销了它,以及在一天、七天和三十天后该设置是否仍保持 DeepSweep 修改后的状态,从不包括文件或其内容)、审查的触发方式、审查耗时、检测到的 AI 编程助手。对于智能体环境审查,还包括智能体拥有哪些类型的访问权限(MCP 工具、shell、数据库、git 写入、部署)、发现的能力与授权缺口数量、整体风险、访问结论、智能体的操作中未受管控、未使用或已对齐的数量、智能体的生命周期状态、审查在智能体配置中发现的明文凭据数量、检查过的智能体配置文件数量以及无法读取或因过大而跳过的数量(仅数量),以及是否检测到 Claude Code。审查发现的让智能体无需询问即可行动、超出项目范围访问或运行未固定版本的 MCP 服务器的设置数量,其中 DeepSweep 可以替你修改的设置数量及其属于哪类设置,找到了哪些助手的设置文件(从不包括文件本身),是否提供了可复制的摘要,检查过的设置文件数量以及无法读取的数量(仅数量),以及 shell 命令是否可以无需询问运行、受到限制、保持智能体默认设置或无法确定。
- **工作区概况:**使用了哪几类语言和软件包生态、包含哪些文件扩展名、有多少个文件夹、是否受信任,以及是否包含 git 仓库、MCP 配置或 Cursor 规则。
- **错误:**错误的类型及其在 DeepSweep 中发生的位置(精确到 DeepSweep 自身代码中的函数和位置)、消息的长度,以及用于归并相同错误的简短单向指纹。绝不包括消息本身,也绝不包括你电脑上的任何路径。
- **标识符:**编辑器为这台机器提供的标识符(编辑器未提供时使用随机生成的标识符)、由其派生的值(其中一个每天更换),登录后还包括你的账户标识符。不包括你的邮箱或用户名。
- **连接状况:**DeepSweep 每次向自身服务发出请求时,记录请求的类别(开始登录、依赖检查、刷新套餐、将这台机器关联到你的账户,或登记安装)、是否得到回应、大致耗时、尝试了几次,以及失败时停在哪一步(查找服务器、建立连接、建立安全连接或等待回应)。绝不包括地址、请求内容或回应内容。
- **位置:**我们的服务器和分析服务商会在每次请求时收到你的 IP 地址,并据此估算大致位置。
使用数据绝不包括源代码、文件内容、文件名或路径(只包括文件扩展名,以及出错时在 DeepSweep 自身代码中的位置)、文件夹名或项目名、错误消息的文本,以及凭据的值。可通过 deepsweep.telemetry.enabled 设置关闭,或使用下文的 DEEPSWEEP_TELEMETRY=off。在 VS Code 中,DeepSweep 还会遵循编辑器自身的遥测设置。
使用数据无法发送时,会保存在这台机器上,最多 7 天、不超过固定大小,并在连接恢复后发送。它只包含原本就会发送的内容,关闭使用数据会将其删除。
功能发出的请求。 这些不属于使用数据,因此使用数据的开关不会阻止它们。DEEPSWEEP_OFFLINE=1 会阻止其中每一项。
- 依赖检查(登录后):你的清单文件声明的注册表软件包的名称与版本,用于确认每个软件包确实存在。本地、git 和 URL 依赖不会发送。
- README 徽章(登录后复制或添加徽章时):审查的发现数量、审查的文件数,以及由工作区位置单向派生的标识符,以便徽章显示你的审查记录。
- **登录:**完成登录所需的请求,以及把这台机器的标识符与你的账户关联。
- 邀请码(你查看邀请码时):读取你的账户状态。
- **更新检查:**向扩展注册表查询最新版本。可通过
deepsweep.checkForUpdates 设置关闭。
- **反馈:**你写下的消息,以及你提供的邮箱(如有),并附带扩展版本和编辑器名称。
DeepSweep 会连接到哪里。 只有三个地方,没有其他。卸载 DeepSweep 不会打开任何页面,也不会发送任何内容。
| 连接到 |
何时 |
发送什么 |
如何关闭 |
us.i.posthog.com 和 api.deepsweep.ai |
使用 DeepSweep 期间,分批发送 |
上文列出的使用数据 |
将 deepsweep.telemetry.enabled 设为 false、设置 DEEPSWEEP_TELEMETRY=off 或 DEEPSWEEP_OFFLINE=1。在 VS Code 中,编辑器自身的遥测设置同样有效 |
api.deepsweep.ai |
DeepSweep 第一次启动时(若那次未成功,则在下次启动时) |
你的环境(编辑器、扩展版本、操作系统、语言、时区)、上文所述的机器标识符,以及你通过推荐链接而来时的推荐码 |
与使用数据相同的开关 |
api.deepsweep.ai |
你登录时,以及登录期间定期进行,用于保持套餐信息最新 |
登录所需的内容,以及这台机器的标识符与你账户的关联 |
保持未登录,或设置 DEEPSWEEP_OFFLINE=1 |
api.deepsweep.ai |
登录后,每次审查之后 |
你的清单文件声明的注册表软件包的名称与版本 |
保持未登录,或设置 DEEPSWEEP_OFFLINE=1 |
api.deepsweep.ai |
登录后复制或添加 README 徽章时 |
发现数量、审查的文件数,以及工作区的单向标识符 |
不复制或添加徽章,或设置 DEEPSWEEP_OFFLINE=1 |
api.deepsweep.ai |
你查看邀请码时;以及登录状态下每个会话最多一次,用于找回你未完成的结账 |
读取你的账户状态 |
设置 DEEPSWEEP_OFFLINE=1 |
api.deepsweep.ai |
登录后你选择升级时 |
你选择的套餐与计费周期,以及你从哪个编辑器开始 |
不在编辑器中升级 |
api.deepsweep.ai |
你发送反馈时 |
你的消息、你提供的邮箱(如有)、扩展版本和编辑器名称 |
不发送反馈 |
open-vsx.org 或 marketplace.visualstudio.com(取决于你从哪里安装) |
DeepSweep 启动后不久,之后每 12 小时一次 |
查询最新版本号 |
将 deepsweep.checkForUpdates 设为 false,或设置 DEEPSWEEP_OFFLINE=1 |
发往 api.deepsweep.ai 的每个请求还会附带扩展版本、编辑器名称以及操作系统与 CPU 架构。需要你账户的请求(套餐、依赖检查、徽章、邀请码与结账)还会附带你的会话。
隔离网络环境请设置 DEEPSWEEP_OFFLINE=1。 设置后,DeepSweep 不会发起任何网络请求——没有遥测、没有依赖检查、没有登录,什么都没有。审查本身不受影响:模式匹配、发现项、诊断、代码镜头、评级与修复建议全部在你的机器上运行,一向如此。离线模式只会关闭需要网络的功能:需要软件包注册表的依赖检查、需要账户服务的登录,以及随之关闭的徽章审查记录发布和更新提醒。
遥测开关: 在启动编辑器前设置环境变量 DEEPSWEEP_TELEMETRY=off,DeepSweep 将不发送任何遥测——没有分析、没有诊断、没有任何遥测网络请求。适用于 CI 机器与企业合规策略;在所有受支持的编辑器中均生效。
错误报告永远不携带你的文件路径。 出现问题时,DeepSweep 只记录问题的类型——某个文件无法读取、某个请求超时——绝不记录消息内容本身,因此目录名、项目名和用户名都不会进入错误报告。
隐私政策
自主智能体工作区(Devin 等)
DeepSweep 也能在无人值守的环境中运行。在 Devin 这类自主智能体环境中,
只需像安装任何编辑器扩展一样,把 DeepSweep 加入机器快照(machine snapshot)——
它会随工作区启动,在打开时审查智能体环境,并在智能体写入文件时持续复查,
与在开发者手中的表现完全一致。它可在 Devin 会话中运行;
除了将扩展装入快照外,无需任何额外配置。
人工安全审计
当一次审查发现了你想要第二意见的问题,或者你希望在上线前对智能体配置做一次全面检查时,DeepSweep 人工安全审计 比任何自动化检查都更深入。安全工程师会依照固定范围的清单审查你的智能体配置、权限与工具链,并交付一份书面报告,用清晰的 [PASS] / [WARN] / [FAIL] 结论标注每项发现及对应的修复步骤。
审计 $99 起;如未发现严重问题,则完全免费。可直接在编辑器的审查面板中预约,或访问 deepsweep.ai/audit。
链接
本页面同时作为两个市场列表的正文,因此两者都列在这里——同一套代码、同一个版本、两个注册表: