Detection rules

Each rule below has a stable ID that appears in every output format, so a finding in CI is the same object as a finding in your terminal. Severity is bounded by evidence: a finding with no witness and no source line is capped below HIGH, because a reader cannot verify it.

AG-001Unrestricted Shell/Code ExecutionCRITICALAG-002Data Exfiltration PathHIGHAG-003Unauthenticated MCP ServerHIGHAG-005Dangerous Tool CombinationsHIGHAG-006No Human Approval for Destructive ActionsHIGHAG-007Hardcoded Secret / CredentialHIGHAG-009Unlimited Sub-Agent SpawningHIGHAG-010No Rate Limiting on High-Risk ToolsMEDIUMAG-011Tool Description Injection / PoisoningHIGHAG-012Unencrypted MCP TransportMEDIUMAG-013Memory/RAG Poisoning RiskHIGHAG-014Delegation Without OversightHIGHAG-015Supply Chain RiskHIGHAG-016Coding Agent: Unrestricted File System ScopeHIGHAG-017Browser Agent: Credential Store AccessHIGHAG-019Context Overflow: Multiple Unbounded Data ToolsMEDIUMAG-021Zero-Width Characters Detected (Invisible Content)HIGHAG-023Self-Modification: File Write Access to Own SourceHIGHAG-024High Cross-Origin Risk: Many MCP Servers ConnectedMEDIUMAG-025Tool ShadowingMEDIUMAG-026Ambient AuthorityCRITICALAG-027Prompt Leakage RiskHIGHAG-COMPCompositional RiskHIGHAG-TRIFECTAInformation-Flow Exfiltration Path (Lethal Trifecta)CRITICAL

Coverage, honestly

24 rules are documented here. The scanner ships more detectors than that; rules without written guidance are deliberately not given placeholder pages, because a page that restates its own title helps nobody. What the rule set as a whole does and does not catch is measured on benchmarks and limits.

pip install lucin
lucin scan .