SecureAI-Scan is an open-source (MIT) static analysis scanner for TypeScript, JavaScript and Python code that calls LLMs or serves MCP tools. It finds prompt injection, sensitive data in prompts and logs, unsafe handling of model output, MCP tool-argument command injection and path traversal, tool poisoning, RAG and vector-store weaknesses, and Agent Skill poisoning. Each finding carries an evidence tier (proven, likely, heuristic) and a source-to-sink trace. It runs offline, and no code is uploaded. It also audits MCP servers and Agent Skills already installed on a machine and generates an AI bill of materials