Security scanner for AI skills, MCP servers. Detects toxic flows, prompt injection, tool poisoning.
422
Security linter and scanner for AI skill files, MCP servers, and agentic AI components. Detects AVE vulnerabilities and produces OWASP AIVSS v0.8 risk scores.
| Image | Engines | Best for |
|---|---|---|
bawbel/scanner:latest · 1.2.3 | Pattern (40 rules) | Lightweight CI pipelines |
bawbel/scanner:full · 1.2.3-full | Pattern + YARA | Recommended for most users |
| Category | Examples |
|---|---|
| Toxic flows | Credential read + exfil chain, tool poisoning + exfil, goal override + exfil |
| Prompt injection | External instruction fetch, goal override, hidden instructions |
| Tool poisoning | Undeclared permission claims, trust manipulation |
| Credential theft | Hardcoded API keys, .env reads, SSH key access |
| Supply chain | Unsafe delegation chains, sub-agent exfiltration |
| Behavioral (Stage 3) | Runtime sandbox: outbound connections, shell injection, persistence |
# Scan a directory (recommended image)
docker run --rm -v $(pwd):/scan:ro bawbel/scanner:full scan /scan --recursive
# Fail CI on high+ severity findings
docker run --rm -v $(pwd):/scan:ro bawbel/scanner:full scan /scan --recursive --fail-on-severity high
# JSON output for SIEM/tooling
docker run --rm -v $(pwd):/scan:ro bawbel/scanner:full scan /scan --recursive --format json
- name: Bawbel security scan
run: |
docker run --rm -v ${{ github.workspace }}:/scan:ro \
bawbel/scanner:full scan /scan --recursive --fail-on-severity high
docker build --build-arg WITH_ALL=true -t bawbel/scanner:custom .
Available build args: WITH_YARA=true, WITH_SEMGREP=true, WITH_LLM=true, WITH_SANDBOX=true, WITH_ALL=true
Content type
Image
Digest
sha256:edf329087…
Size
55.2 MB
Last updated
4 months ago
docker pull bawbel/scanner