aicoolies logo
MEDUSA logo
MEDUSA logo

MEDUSA

AI-first security scanner for LLM, agent, MCP, and RAG codebases

open sourceverified Aug 24, 2026

MEDUSA is an AGPL-3.0 AI-first security scanner from Pantheon Security that checks AI and machine-learning applications, LLM agents, MCP workflows, RAG pipelines, repository-poisoning risks, secrets, and agent-specific compromise patterns.

MEDUSA from Pantheon Security is an AI-focused security scanner for repositories and application workflows that include machine-learning code, LLM integrations, agents, MCP components, or RAG pipelines. Its CLI-oriented workflow is designed to bring AI-specific checks into developer and DevSecOps review paths.

Official project materials highlight detection areas such as prompt injection, MCP vulnerabilities, RAG and repository poisoning, secrets, and compromise patterns involving agent-development environments. Those checks complement conventional scanning by focusing on risks introduced by prompts, retrieval content, tool connections, and AI-oriented project files.

MEDUSA is licensed under AGPL-3.0-or-later, which can affect deployment and redistribution decisions and should be reviewed before organizational adoption. Detection coverage and rule-count claims are point-in-time project claims, and the scanner should complement rather than replace complete SAST, SCA, secrets management, dependency review, and human security testing.

Pricing

100% free and open source ($0 software cost). MEDUSA by Pantheon Security is an open-source multi-agent cybersecurity framework for auditing Solidity smart contracts and detecting Web3/DeFi vulnerabilities with zero licensing fees.

full pricing breakdown →

Platforms

Python package and CLI for scanning repositories and AI application code, including LLM, agent, MCP, and RAG security patterns.

Categories

Tags

Use Cases

Related Tools

computed discovery: shared active categories · kept separate from editor-verified Alternatives

OpenLIT logo

OpenLIT

OpenTelemetry-native observability for LLM applications with evals and GPU monitoring

OpenLIT is an open-source AI engineering platform that provides OpenTelemetry-native observability for LLM applications. It combines distributed tracing, evaluation, prompt management, a secrets vault, and GPU telemetry in a single self-hostable stack. With 50+ integrations across LLM providers and frameworks, it lets teams monitor AI applications using their existing observability backends like Grafana, Datadog, or Jaeger.

Open Source
Cilium logo

Cilium

eBPF-based networking, security, and observability for Kubernetes

Cilium is a CNCF Graduated, Apache-2.0 project for Kubernetes networking, security, and observability using eBPF. It can replace kube-proxy, enforce identity-aware L3-L7 network policies, and add Hubble flow observability plus Tetragon runtime-security signals. Current source checks support GKE Dataplane V2 using Cilium/eBPF and Azure CNI Powered by Cilium for AKS.

Open Source
Act logo

Act

Run GitHub Actions locally for fast feedback

Act is an open-source tool that runs GitHub Actions workflows locally using Docker containers that match GitHub's execution environment. It provides instant feedback on workflow changes without pushing to a repository, supports matrix builds, secret management, and artifact handling. Act can also replace Makefiles by using workflow files as task definitions, making it useful for both CI/CD development and local task automation across development teams.

Open Source
Pangolin logo

Pangolin

Identity-aware VPN and reverse proxy for zero-trust remote access

Identity-based remote access platform built on WireGuard that combines reverse proxy and VPN capabilities. Pangolin supports clientless browser access for web apps and client-based private-resource access across macOS, iOS, Windows, Linux, and Android, with zero-trust rules, peer-to-peer tunnels, automatic SSL, SSO/OIDC options, and cloud or self-hosted deployment.

freemium
ArgoCD logo

ArgoCD

Declarative GitOps continuous delivery tool for Kubernetes.

Argo CD is the most popular GitOps continuous delivery tool for Kubernetes. It continuously monitors Git repositories and automatically syncs application state to match the desired configuration. A CNCF graduated project used by thousands of organizations for deploying to Kubernetes clusters.

Open Source
Blacksmith logo

Blacksmith

Run GitHub Actions on faster bare-metal runners with lower Ubuntu per-minute pricing

Blacksmith is a drop-in replacement for GitHub-hosted runners that executes Actions on bare-metal gaming CPUs and source-shaped cache infrastructure. Migration requires a one-line YAML change. Features include colocated warm caches, persistent Docker layer caching on NVMe, CI observability with log search, and Firecracker microVM isolation. SOC 2 Type 2 certified, with Ubuntu x64 pricing at $0.004/min and 3,000 free minutes/month.

freemium

Used in Stacks

FAQ

What is MEDUSA?

MEDUSA is an AGPL-3.0 AI-first security scanner from Pantheon Security that checks AI and machine-learning applications, LLM agents, MCP workflows, RAG pipelines, repository-poisoning risks, secrets, and agent-specific compromise patterns.

Is MEDUSA free?

Yes — MEDUSA is open source and free to use. 100% free and open source ($0 software cost). MEDUSA by Pantheon Security is an open-source multi-agent cybersecurity framework for auditing Solidity smart contracts and detecting Web3/DeFi vulnerabilities with zero licensing fees.

Is MEDUSA open source?

Yes — MEDUSA is open source.

Is MEDUSA still maintained?

Yes — MEDUSA is active. Its listing was last verified on August 24, 2026.