wirecheck
Dependency & change-impact mapping

Know what breaks before you change an AI agent.

Map agents, tools, credentials, integrations and workflows, then see the impact before you remove, revoke or replace them.

CustomerSupportAgent
AI agent · 3 dependencies
Claude
Credential
Zendesk MCP
MCP server
Slack
Credential
Scan complete3 agents9 dependencies2 mcp servers1 unknown

Every agent sits on the same chain of dependencies. This is exactly what the deterministic detectors look for in your code — nothing more, nothing inferred.

Agent→MCP server→Credential

The hard part isn't building the agent.

It's knowing what depends on it six months later.

Without visibility
Agent
?
?
?
?
With dependency mapping
Agent
├── Claude (credential)
├── Zendesk MCP
└── Slack (credential)
Try it

What happens if I remove this?

Select an operation and watch the blast radius light up, and what stays quiet.

What happens if I…
usesusesusesusesusestriggersusesinvokes

Know what you don't know.

A dependency map that quietly drops what it can't resolve looks complete when it isn't. An unresolved reference stays on the map on every scan, not just the demo above.

KNOWN
✓ Salesforce
✓ Slack
✓ Zendesk MCP
✓ PostgreSQL
UNKNOWN
? customer-sync webhook
? external scheduled job

From dependency graph to retirement plan.

Not just a graph. A checklist ordered by what has to happen first.

Before you revoke Claude
  • ✓Confirm support-agent.ts can tolerate losing this
  • ⚠Revoke Salesforce OAuth grant
  • ?Investigate customer-sync webhook
  • ✓Re-run scan and confirm no consumers remain
At scale

One demo agent is easy. Your whole org isn't.

This is what a platform engineer sees after connecting every repo their team owns: not one graph, but a portfolio of them.

Org overview
12 repositories28 credentials11 MCP servers16 agents5 unknown
Search repositories, credentials, agents…
AllNeeds reviewHas unknownsStale credentials
RepositoryCredentialsMCPAgentsUnknownStatus
payments-api3120OK
support-agent-repo2211Review
billing-worker4010OK
internal-tools1100OK
data-pipeline2030OK
legacy-crm-sync5102Stale credential
growth-experiments1241Review
infra-scripts2000OK
onboarding-flow2110OK
analytics-worker3020OK
sales-enablement-bot2321Review
notification-service1000OK
⚠ SALESFORCE_LEGACY_KEY is referenced in legacy-crm-sync only, last seen used 214 days ago in that repo's history. Nothing else in the org depends on it.
Cross-repo impact

Click into any credential and it's merged across every repository that references it by name, so “what breaks if I revoke this?” means the whole org, not just the repo you happened to be looking at.

ANTHROPIC_API_KEY
Credential · same name, referenced in 3 repositories
HIGH
  • SupportAgentsupport-agent-repo
    src/agents/support-agent.ts:4
  • OutreachAgentgrowth-experiments
    src/agents/outreach-agent.ts:9
  • SummarizeScriptinternal-tools
    scripts/summarize.ts:2
If you revoke this: 3 repositories affected, 3 consumers break. Not just the one you happened to be looking at.
Zendesk MCP
MCP server · same name, referenced in 2 repositories
HIGH
  • SupportAgentsupport-agent-repo
    mcp.json:8
  • SalesBotsales-enablement-bot
    mcp.json:3
If you revoke this: 2 repositories affected. Disabling it breaks ticket lookups in both, at once.
Recent activity
All repositories
  • 3m agolegacy-crm-syncScan complete2 unresolved references found
  • 41m agogrowth-experimentsScan complete1 new agent detected (OutreachAgent)
  • 1h agopayments-apiScan completeno changes since last scan
  • 2h agosupport-agent-repoImpact analysis runREVOKE Claude, 2 direct consumers
  • 5h agointernal-toolsScan complete1 credential, 1 MCP server
  • 1d agosales-enablement-botScan complete1 unresolved reference found

A real scanner underneath, not just a dashboard.

Deterministic detection first. An LLM is only ever asked to summarize what was already found, never to invent a dependency.

scan: kev-er/support-agent-repo
Scanning repository...
 
✓ 3 agents detected
✓ 9 dependencies detected
✓ 2 MCP servers detected
✓ 4 credentials detected
 
1 unknown relationship
 
Scan complete.
 
impact: CustomerSupportAgent --remove
 
Potential impact:
 
6 systems affected
1 workflow
2 integrations
1 credential
 
Unknown:
customer-sync webhook
Unknown→Mapped→Understood

Stop guessing what your agents depend on.

Built for the engineer who gets asked “can we safely revoke this token?”