What's Behind Your Agent Environment Review
Review your AI. Ship with confidence. The verified CVEs and the shipped detection patterns behind your Repo Grade and Deploy Risk across Antigravity, Trae, Devin Desktop, Cursor, Claude Code, and GitHub Copilot — and 8 more agentic tools — including the Amazon Q extension compromise. Every CVE here is checked against the MITRE record; every pattern named here ships in the extension.
CVE Database
| CVE ID | Severity | Affected IDE | Attack Pattern | Detection |
|---|---|---|---|---|
| CVE-2025-53773 | ACTION (7.8) | GitHub Copilot | Prompt Injection → Auto-Approve → Command Execution | DS-PI-001: Instruction Override — the review flags override attempts in the instruction files this attack rides in on |
| CVE-2025-54135 | ACTION (8.6) | Cursor | Malicious MCP Server → Unapproved Workspace Write → Code Execution | DS-MCP-001: Unrestricted MCP Tool Access |
| CVE-2025-55284 | ACTION (7.5) | Claude Code | Prompt Injection → Confirmation Bypass → DNS Exfiltration | DS-EXFIL-001: Data Exfiltration Pattern |
| CVE-2025-8217 | ACTION (9.1) | Amazon Q | Compromised Extension Release → Injected Prompt → Destructive Operations | No shipped pattern covers a compromised marketplace extension today. The Amazon Q environment review covers its agent configuration; extension supply-chain review is on the roadmap and is not claimed here. |
| CVE-2025-6514 | ACTION (9.6) | All MCP Clients | Untrusted MCP Server → Authorization Flow → Command Injection | DS-MCP-002: Remote MCP Server |
Detection Patterns by Category
The 37 AI-specific patterns below ship in the extension today, listed verbatim. Alongside them ship 40 traditional secure-coding patterns, for 77 in total.
Credential Exposure (16)
- DS-SEC-001: Hardcoded API Key
- DS-SEC-002: AWS Access Key
- DS-SEC-003: Private Key Material
- DS-SEC-004: Connection String with Credentials
- DS-SEC-005: JWT Secret or Token
- DS-SEC-006: Stripe Key
- DS-SEC-007: Generic Secret Assignment
- DS-SEC-008: GCP Service Account Key
- DS-SEC-009: Slack Bot/User Token
- DS-SEC-010: SendGrid API Key
- DS-SEC-011: Twilio Credentials
- DS-SEC-012: Azure Client Secret
- DS-SEC-013: Firebase/Google API Key
- DS-SEC-014: Mailgun API Key
- DS-SEC-015: Slack Webhook URL
- DS-SEC-016: .env File with Secrets
Prompt Injection (7)
- DS-PI-001: Instruction Override
- DS-PI-002: Role Reassignment
- DS-PI-003: Hidden Instruction in Comment
- DS-PI-004: Invisible Unicode Characters
- DS-PI-005: Bidirectional Text Override
- DS-PI-006: Base64-Encoded Payload in Rules
- DS-PI-007: Hidden Content Block
MCP Security (7)
- DS-MCP-001: Unrestricted MCP Tool Access
- DS-MCP-002: Remote MCP Server
- DS-MCP-003: Overly Permissive Deno Args
- DS-MCP-004: Sensitive Env Vars in MCP Config
- DS-MCP-005: MCP Auth Disabled
- DS-MCP-006: MCP Wildcard Permissions
- DS-MCP-007: MCP Unrestricted Network Access
Misconfiguration (4)
- DS-CFG-001: Missing .gitignore for Secrets
- DS-CFG-002: Debug Mode Enabled
- DS-CFG-003: CORS Allow All Origins
- DS-CFG-004: Disabled SSL Verification
Data Exfiltration (2)
- DS-EXFIL-001: Data Exfiltration Pattern
- DS-EXFIL-002: External Webhook in Rules
Supply Chain (1)
- DS-SC-001: Wildcard Dependency Version
Reviewed Agent Environments
DeepSweep reviews each environment's agent configuration. Reviewing is not runtime protection, and no audience figures are claimed here.
Start Protecting Your Code Today
Install DeepSweep in under 2 minutes. Free forever for individual developers.