Find AI agent exposure before attackers do

Run a free GitHub scan for AI frameworks, MCP servers, exposed secrets, privileged workflows, prompt-injection surfaces, attack paths, and remediation actions.

GitHub scan MCP review Secrets CI/CD Remediation
Agentic Exposure Scanner Evidence only
01
Connect GitHub repositoryPublic repos or read-only token
02
Detect AI/MCP footprintFrameworks, tools, prompts, configs
03
Find exposed privilegeSecrets, workflows, data access
04
Generate attack pathsPrompt injection to business impact
05
Export remediation planOwner, effort, validation, proof

Use the free scanner to see where AI risk starts.

The free scanner is the first diagnostic layer after workspace creation: connect a GitHub repository, inspect AI-agent exposure, and export evidence your technical team can verify. Paid engagements add private review, business impact analysis, remediation ownership, and control-plane planning.

01

Choose a repository

Paste `owner/repo`, a GitHub URL, or connect GitHub with a read-only token for private repositories and higher API limits.

02

Run an exposure scan

Diomedi reads real repository files and looks for agent frameworks, MCP configs, prompt surfaces, secrets, tool use, data access, and workflow privilege.

03

Prioritize the risk

Findings are ranked by severity and tied to files, evidence, likely owner, effort, validation step, and attack-path context.

04

Export proof

Download an executive markdown report, raw JSON evidence, and a remediation plan that can be reviewed by engineering or security leadership.

Included in the free scanner

  • Public GitHub repository scanning
  • Optional read-only token for private repo scans
  • AI framework, MCP, secrets, CI/CD, prompt, tool, and data-signal detection
  • Attack-path generation from repository evidence
  • Executive report, JSON evidence, and remediation export

Unlocked in a private assessment

  • Multi-repository scope and manual evidence review
  • Business-impact scoring tied to revenue, customers, compliance, and production access
  • Executive risk narrative for founders, CISOs, investors, or procurement teams
  • Prioritized remediation roadmap with ownership and validation plan
  • Control-plane pilot design for approvals, policies, audit trail, and agent registry

The security perimeter now includes workers that are not human.

AI agents can query databases, draft payments, modify repositories, trigger workflows, send messages, and call tools. Most companies cannot answer who owns them, what they can access, or how to shut them down.

01

Unknown inventory

Agents, bots, service accounts, API keys, and automations spread across tools without a central owner.

02

Excessive permissions

Non-human workers accumulate read, write, export, and spend capabilities faster than security reviews can track.

03

No human gate

High-risk actions execute without approvals, audit context, emergency revoke, or policy evidence.

Start with a scanner. Expand into a control plane.

The current product helps you prove risk quickly. The paid pilot adds teams, approvals, policy, persistent evidence, and connectors.

Current: repo scannerScan GitHub for AI frameworks, MCP configs, exposed secrets, privileged workflows, and tool/data signals.
Current: risk evidenceGenerate prioritized findings, attack paths, executive report, JSON evidence, and remediation plan.
Pilot: agent registryMap every AI agent, automation, MCP server, API key, service account, and bot to an owner.
Pilot: approvalsRequire human decisions for production writes, data exports, payment actions, and sensitive workflows.
Enterprise: signed audit logsStore immutable evidence for leadership, compliance reviews, incident response, and procurement.
Enterprise: SSO and connectorsAdd GitHub orgs, Slack, cloud IAM, Supabase, CI/CD, and model/runtime telemetry.

Request a private AI agent risk assessment.

Diomedi is built for companies where AI agents, MCP tools, repositories, credentials, and CI/CD permissions are already close to production. The engagement is scoped after qualification, so small teams are not overcharged and large companies do not receive a lightweight checklist.

Evidence first Executive-ready Remediation included

Recommended path AI Agent Risk Audit

A focused assessment for teams that need a real inventory, attack-path review, executive report, and remediation plan.

Engagement scope is private and based on risk, company scale, urgency, and required evidence. Qualified requests receive a scoped proposal.

What Diomedi scans for.

Designed for software companies shipping AI agents, MCP tools, internal copilots, autonomous workflows, and AI-assisted engineering systems.

AI agent securityFind agent frameworks, tool calling, autonomous action surfaces, and prompt-controlled operations.
MCP server securityDetect MCP configs that expose filesystem, shell, remote runtime, or business-system access.
Secret exposureIdentify credential-like patterns and explain how they can combine with agents or CI/CD workflows.
CI/CD privilegeReview GitHub Actions triggers, write permissions, secrets, scripts, dispatch events, and OIDC risk.
Attack pathsChain findings into realistic business-impact paths for security, founders, and investors.
Remediation planGenerate owner, effort, action, validation, and evidence files for every high-priority task.

Built for serious buyers, even in V1.

The first module is lightweight, cloud-friendly, and evidence-first. The enterprise roadmap is explicit.

Real GitHub API scan No fictional default data Token not stored Report and remediation export Vercel and Netlify deploy-ready

Engagements are scoped to business risk.

The same scanner can support a startup audit, a procurement blocker, or a multi-team control-plane pilot. Diomedi qualifies the account first, then proposes the smallest engagement that can produce board-ready evidence.

AI agent security FAQ.

Short answers for security leaders, founders, and technical buyers evaluating Diomedi.

Is Diomedi only a demo?

No. The current scanner calls the GitHub API, reads repository files, detects evidence, generates findings, builds attack paths, and exports reports. The enterprise login, persistent teams, SSO, and signed logs are the next paid pilot layer.

Do I need an account to try it?

Yes. Public repository scans are free after workspace creation. Registration keeps each scan attached to a buyer profile, audit follow-up, and pilot onboarding path.

Does Diomedi store my GitHub token?

No. The optional token is used in memory for a private repository or higher rate limit scan and is not saved to browser storage.

Who is this for?

Software companies using AI agents, MCP servers, internal copilots, AI automation, GitHub Actions, API keys, service accounts, or autonomous workflows.

Why would companies pay?

The free scanner proves the direction of risk. The private assessment turns that evidence into an inventory, attack-path review, executive report, remediation plan, and pilot proposal tied to the company's size, urgency, compliance pressure, and production exposure.