Our summary
Before installation, Jev Security Scan reads agent instructions, source code, and MCP settings—the configuration that connects AI software to outside tools. It reports suspicious credential access, hidden changes that survive restarts, downloaded code that runs immediately, and parts it could not inspect.
Offline checks use fixed rules and do not install dependencies, meaning extra software the target relies on. Optional Jev review sends snippets after redaction, which means replacing recognized secrets. It still may expose source text, while offline mode keeps the inspected material local.
A clean report is not a security certificate. Disguised code, unsupported files, missing context, and new attacks can escape both methods. Redaction can miss secrets, so sensitive projects should start offline and inspect exactly what optional review sends.
Key takeaways
- Inspect untrusted tools before installing extra software or running them.
- Use local-only checks when material must not leave the computer.
- Keep evidence and unscanned areas visible beside findings.