> ## Documentation Index
> Fetch the complete documentation index at: https://docs.switchagents.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs moved from docs.flintai.dev to docs.switchagents.ai. Use docs.switchagents.ai for every link and request.
> To search these docs from an AI tool, connect the MCP server at https://docs.switchagents.ai/mcp. The page index is at https://docs.switchagents.ai/llms.txt.

# Discover your agents

> Scan your GitHub repository and see every AI agent in your code

Connect a GitHub repository and Flint AI scans your code for AI agents. You end up with an
inventory of every agent discovered in the repo — each with its highest severity and total issue
count — along with the models, tools, and MCP servers it uses.

<Card title="Flint AI on GitHub" icon="github" href="https://github.com/sandbox-quantum/flintai-cli">
  Source code, example agents, and issue tracking
</Card>

<Note>
  **Before you start, you'll need:**

  * A GitHub repository containing Python agent code
  * A Flint AI API key
  * An API key for an LLM provider — Google Gemini, OpenAI, or Anthropic. The scanner uses it
    to analyze your agent code. Google Gemini has a free tier, so you can scan at no cost.

  **Supported frameworks:** Google ADK, Google GenAI, Anthropic, OpenAI, OpenAI Agents SDK,
  LangGraph, CrewAI, AutoGen, HuggingFace Transformers, HuggingFace smolagents
</Note>

<Accordion title="Where to get an LLM provider key">
  * **Google Gemini:** [aistudio.google.com/apikey](https://aistudio.google.com/apikey) (free tier available)
  * **OpenAI:** [platform.openai.com/api-keys](https://platform.openai.com/api-keys)
  * **Anthropic:** [console.anthropic.com/settings/keys](https://console.anthropic.com/settings/keys)
</Accordion>

## Scan your repository

<Steps>
  <Step title="Get your Flint AI API key">
    In [Flint AI](https://app.flintai.dev), go to **Settings**, then **API Keys**, and
    create a key.

    <Note>
      Copy your key immediately when created — it is shown only once. Keep it somewhere secure and
      never commit it to version control. In the next step you'll add it as an encrypted GitHub
      Actions secret rather than pasting it into the workflow file.
    </Note>
  </Step>

  <Step title="Add the scan workflow to your repository">
    Create `.github/workflows/flintai-inventory-scan.yml` with:

    ```yaml theme={null}
    name: Flint AI inventory scan
    on:
      workflow_dispatch:
      schedule:
        - cron: "0 10 * * 1-5"
    jobs:
      inventory-scan:
        runs-on: ubuntu-latest
        steps:
          - name: Check out repository
            uses: actions/checkout@v5
          - name: Run Flint AI inventory scan
            uses: sandbox-quantum/flintai-codescan-action@v5
            with:
              flintai_instance: https://app.flintai.dev
              flintai_token: ${{ secrets.FLINTAI_TOKEN }}
              llm_model: google:gemini-3.5-flash
              llm_api_key: ${{ secrets.LLM_API_KEY }}
    ```

    The workflow reads two secrets. In your repository, go to **Settings**, then
    **Secrets and variables**, then **Actions**, and add:

    * `FLINTAI_TOKEN` — the Flint AI API key from the previous step.
    * `LLM_API_KEY` — your LLM provider API key.

    <Accordion title="Choose a model">
      `llm_model` takes a `provider:model` value. The provider prefix tells the scanner
      which API key it is using:

      ```
      anthropic:claude-opus-4-8       # Anthropic
      openai:gpt-5.4                   # OpenAI
      google:gemini-3.5-flash          # Google Gemini
      ```

      Whichever provider you name, its key goes in the `LLM_API_KEY` secret.
    </Accordion>

    <Accordion title="What the scan does">
      The Action scans your repository for AI agents, finds security issues and
      misconfigurations, and sends results to your workspace. It needs only read access to
      your code and does not modify your repository. The `schedule` in the workflow keeps
      your inventory current as your code changes.
    </Accordion>

    <Accordion title="Share the secrets across repositories">
      Scanning more than one repository? Define `FLINTAI_TOKEN` and `LLM_API_KEY` at the
      organization level so every repository shares them.
    </Accordion>

    <Accordion title="Instance URL doesn't need to be secret">
      Your instance URL is not sensitive, so `flintai_instance` is a plain value, not a
      secret. `https://app.flintai.dev` is the standard instance; other environments exist
      and use the same input.
    </Accordion>
  </Step>

  <Step title="Run the scan and see your agents">
    The workflow runs on the schedule in the file. To start it manually at any time: open the
    **Actions** tab in your repository, select **Flint AI inventory scan**, then
    **Run workflow**. The scan step takes a minute or two.

    To confirm results landed, go to **Settings**, then **Data sources** in Flint AI.
    Select **GitHub** and expand the **Scans** tab — it lists each connected repository
    with the time of its most recent scan. A fresh timestamp means your results arrived.

    <Warning>
      Check the **Scans** tab, not the **Connected** status. The status indicator does not
      yet reflect a live connection check, so it can read Connected before your first scan
      has run.
    </Warning>

    Now open the **Agents** page. Your discovered agents appear in the inventory, each with
    its highest severity and total issue count.

    <Tip>
      **Multi-repo support:** Connect more repositories to see all your agents in one
      workspace. Each agent traces back to its source repository and file path.
    </Tip>
  </Step>
</Steps>

## Next steps

<CardGroup cols={2}>
  <Card title="Read your discovery results" icon="triangle-exclamation" href="/switch-trust/discovery/results">
    Work out what needs attention first, whether a finding is real, and when it's resolved
  </Card>

  <Card title="Monitor and protect" icon="shield-halved" href="/switch-trust/getting-started/runtime">
    Install the SDK to monitor sessions and configure runtime protection
  </Card>
</CardGroup>
