Sign inSign up

bawbel/scanner

By bawbel

•Updated 4 months ago

Security scanner for AI skills, MCP servers. Detects toxic flows, prompt injection, tool poisoning.

Image
Security
2

422

bawbel/scanner repository overview

⁠Bawbel Scanner

Security linter and scanner for AI skill files, MCP servers, and agentic AI components. Detects AVE vulnerabilities and produces OWASP AIVSS v0.8 risk scores.

⁠Images

ImageEnginesBest for
bawbel/scanner:latest · 1.2.3Pattern (40 rules)Lightweight CI pipelines
bawbel/scanner:full · 1.2.3-fullPattern + YARARecommended for most users

⁠What it detects

CategoryExamples
Toxic flowsCredential read + exfil chain, tool poisoning + exfil, goal override + exfil
Prompt injectionExternal instruction fetch, goal override, hidden instructions
Tool poisoningUndeclared permission claims, trust manipulation
Credential theftHardcoded API keys, .env reads, SSH key access
Supply chainUnsafe delegation chains, sub-agent exfiltration
Behavioral (Stage 3)Runtime sandbox: outbound connections, shell injection, persistence

⁠Quick start

# Scan a directory (recommended image)
docker run --rm -v $(pwd):/scan:ro bawbel/scanner:full scan /scan --recursive

# Fail CI on high+ severity findings
docker run --rm -v $(pwd):/scan:ro bawbel/scanner:full scan /scan --recursive --fail-on-severity high

# JSON output for SIEM/tooling
docker run --rm -v $(pwd):/scan:ro bawbel/scanner:full scan /scan --recursive --format json
⁠GitHub Actions
  - name: Bawbel security scan
    run: |
      docker run --rm -v ${{ github.workspace }}:/scan:ro \
        bawbel/scanner:full scan /scan --recursive --fail-on-severity high
⁠Build with all engines
  docker build --build-arg WITH_ALL=true -t bawbel/scanner:custom .

Available build args: WITH_YARA=true, WITH_SEMGREP=true, WITH_LLM=true, WITH_SANDBOX=true, WITH_ALL=true

Tag summary

Content type

Image

Digest

sha256:edf329087…

Size

55.2 MB

Last updated

4 months ago

docker pull bawbel/scanner