Bawbel Scanner MCP server
Scan MCP servers and skill files for AVE vulnerabilities. Conformance scoring and threat intel.
2 stars35 downloads/wk
Reviews
Write oneNobody has reviewed Bawbel Scanner yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Bawbel Scanner tools (10, 1 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
accept_findingwrite actionInsert a justified suppression comment into a skill file.
check_conformanceScore an MCP server manifest against the MCP specification.
check_pinsCheck a directory for skill file rug pull drift.
list_aveList AVE records with optional filters.
lookup_aveGet the full AVE record for a specific vulnerability ID.
scan_chainDelegation chain scan of skill file content.
scan_contentScan raw text content for AVE security vulnerabilities.
scan_credsCredential-focused scan of skill file content.
scan_server_cardFetch and scan an MCP server-card for security vulnerabilities.
search_aveSearch AVE records by keyword.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan3 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 127 days ago8/15
- Maintainer identityregistry namespace matches repository owner7/10
Install Bawbel Scanner in Claude Code, Cursor or VS Code
claude mcp add bawbel-mcp -- uvx bawbel-mcp
What the publisher says
From the Bawbel Scanner repository's README, as published. We do not edit it. Read it on GitHub
Bawbel MCP Server
<!-- mcp-name: io.github.bawbel/bawbel-mcp -->
Security scanner for MCP servers and agentic AI components, exposed as MCP tools.
Bawbel MCP Server lets any MCP-compatible agent scan servers, check skill files, score conformance, manage justified suppressions, and query the AVE threat intelligence database mid-conversation.
Install
pip install bawbel-mcpOr with all detection engines (YARA, Semgrep, LLM, Magika, Sandbox):
pip install "bawbel-mcp[all]"Tools
Resources
Usage
Claude Desktop
Add to claudedesktopconfig.json:
{
"mcpServers": {
"bawbel": {
"command": "uvx",
"args": ["bawbel-mcp"]
}
}
}Claude Code
claude mcp add bawbel uvx bawbel-mcpCursor / Windsurf
Add to your MCP settings:
{
"bawbel": {
"command": "uvx",
"args": ["bawbel-mcp"]
}
}Remote deployment (Streamable HTTP)
uvx bawbel-mcp --transport streamable-http --host 0.0.0.0 --port 8000Example conversations
Scan a server before connecting:
"Before I add this MCP server to my config, scan it for security issues:
https://api.some-mcp-server.com"
Claude calls scanservercard("https://api.some-mcp-server.com") and reports findings with AVE IDs, AIVSS severity scores, and remediation steps.
Check a skill file:
"Check this skill file content for prompt injection vulnerabilities"
Claude calls scan_content(content) and returns findings including any toxic flow chains detected.
Check for hardcoded credentials:
"Does this skill file contain any hardcoded API keys or secrets?"
Claude calls scan_creds(content) and returns credential findings only.
Check for unsafe delegation:
"Does this skill spawn sub-agents without proper trust boundaries?"
Claude calls scan_chain(content) and returns delegation chain findings.
Accept a false positive:
"Mark AVE-2026-00001 on line 7 of travel.md as a false positive.
Reason: internal registry endpoint, not attacker-controlled."
Claude calls accept_finding(...) and writes the justified suppression comment directly into the file. The approval is tracked in version control.
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Bawbel Scanner: common questions
- Is Bawbel Scanner MCP server safe?
- Mostly: it is graded B (80/100). Read the Bawbel Scanner safety report
- How do I install Bawbel Scanner?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Bawbel Scanner need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Bawbel Scanner maintained?
- The last commit was 127 days ago (2026-05-23). The latest release is v1.1.0.
- What can I use instead of Bawbel Scanner?
- Servers from other publishers that do the same job: Scan MCP server, Diemdesk MCP server and Wireshark MCP server. Compare all Bawbel Scanner alternatives.
Alternatives to Bawbel Scanner
Same job from other publishers: the closest match first, then the best rated.
- ScanMCP server for scanner discovery and batch capture via SANEnot reviewedGrowingA
- DiemdeskConvert Office files and PDFs, OCR a scan, or capture a web page — from your assistant.not reviewedGrowingB
- WiresharkProfessional network analysis with tshark. Security audits, deep-dives, and threat detection.not reviewedEstablishedA
- Autopilot JobhuntAgentic job hunt: scan careers pages, score against your resume, draft applications. Never applies.not reviewedGrowingA
- CodeInspectusLocal-first MCP security scanner and CLI for AI-generated applications.not reviewedGrowingC