Mmcp.market

Bawbel Scanner MCP server

by bawbel·io.github.bawbel/bawbel-mcp·v1.1.0·2 stars

Scan MCP servers and skill files for AVE vulnerabilities. Conformance scoring and threat intel.

B80/100grade B
What users say
No reviews yet
Be the first
Safety scan
B80/100

full report

Adoption
New

2 stars35 downloads/wk

Reviews

Write one

Nobody has reviewed Bawbel Scanner yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Bawbel Scanner tools (10, 1 write)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • accept_findingwrite action

    Insert a justified suppression comment into a skill file.

  • check_conformance

    Score an MCP server manifest against the MCP specification.

  • check_pins

    Check a directory for skill file rug pull drift.

  • list_ave

    List AVE records with optional filters.

  • lookup_ave

    Get the full AVE record for a specific vulnerability ID.

  • scan_chain

    Delegation chain scan of skill file content.

  • scan_content

    Scan raw text content for AVE security vulnerabilities.

  • scan_creds

    Credential-focused scan of skill file content.

  • scan_server_card

    Fetch and scan an MCP server-card for security vulnerabilities.

  • search_ave

    Search AVE records by keyword.

Public scan report

scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it

no findings
  • Code scan3 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 127 days ago8/15
  • Maintainer identityregistry namespace matches repository owner7/10
Overall 80/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Bawbel Scanner in Claude Code, Cursor or VS Code

claude mcp add bawbel-mcp -- uvx bawbel-mcp
Add to Cursor

What the publisher says

From the Bawbel Scanner repository's README, as published. We do not edit it. Read it on GitHub

Bawbel MCP Server

<!-- mcp-name: io.github.bawbel/bawbel-mcp -->

Security scanner for MCP servers and agentic AI components, exposed as MCP tools.

Bawbel MCP Server lets any MCP-compatible agent scan servers, check skill files, score conformance, manage justified suppressions, and query the AVE threat intelligence database mid-conversation.

Install

pip install bawbel-mcp

Or with all detection engines (YARA, Semgrep, LLM, Magika, Sandbox):

pip install "bawbel-mcp[all]"

Tools

Resources

Usage

Claude Desktop

Add to claudedesktopconfig.json:

{
  "mcpServers": {
    "bawbel": {
      "command": "uvx",
      "args": ["bawbel-mcp"]
    }
  }
}

Claude Code

claude mcp add bawbel uvx bawbel-mcp

Cursor / Windsurf

Add to your MCP settings:

{
  "bawbel": {
    "command": "uvx",
    "args": ["bawbel-mcp"]
  }
}

Remote deployment (Streamable HTTP)

uvx bawbel-mcp --transport streamable-http --host 0.0.0.0 --port 8000

Example conversations

Scan a server before connecting:

"Before I add this MCP server to my config, scan it for security issues:

https://api.some-mcp-server.com"

Claude calls scanservercard("https://api.some-mcp-server.com") and reports findings with AVE IDs, AIVSS severity scores, and remediation steps.

Check a skill file:

"Check this skill file content for prompt injection vulnerabilities"

Claude calls scan_content(content) and returns findings including any toxic flow chains detected.

Check for hardcoded credentials:

"Does this skill file contain any hardcoded API keys or secrets?"

Claude calls scan_creds(content) and returns credential findings only.

Check for unsafe delegation:

"Does this skill spawn sub-agents without proper trust boundaries?"

Claude calls scan_chain(content) and returns delegation chain findings.

Accept a false positive:

"Mark AVE-2026-00001 on line 7 of travel.md as a false positive.

Reason: internal registry endpoint, not attacker-controlled."

Claude calls accept_finding(...) and writes the justified suppression comment directly into the file. The approval is tracked in version control.

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Bawbel Scanner: common questions

Is Bawbel Scanner MCP server safe?
Mostly: it is graded B (80/100). Read the Bawbel Scanner safety report
How do I install Bawbel Scanner?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Bawbel Scanner need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Bawbel Scanner maintained?
The last commit was 127 days ago (2026-05-23). The latest release is v1.1.0.
What can I use instead of Bawbel Scanner?
Servers from other publishers that do the same job: Scan MCP server, Diemdesk MCP server and Wireshark MCP server. Compare all Bawbel Scanner alternatives.

Alternatives to Bawbel Scanner

Same job from other publishers: the closest match first, then the best rated.

All Bawbel Scanner alternatives →
  • Scan
    MCP server for scanner discovery and batch capture via SANE
    A
  • Diemdesk
    Convert Office files and PDFs, OCR a scan, or capture a web page — from your assistant.
    B
  • Wireshark
    Professional network analysis with tshark. Security audits, deep-dives, and threat detection.
    A
  • Autopilot Jobhunt
    Agentic job hunt: scan careers pages, score against your resume, draft applications. Never applies.
    A
  • CodeInspectus
    Local-first MCP security scanner and CLI for AI-generated applications.
    C

More from bawbel →