Bawbel Scanner MCP server
Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
11 stars63 downloads/wk
Reviews
Write oneNobody has reviewed Bawbel Scanner yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Bawbel Scanner tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan47 source files scanned15/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 16 days ago15/15
- Maintainer identityregistry namespace matches repository owner7/10
Findings (2)
- mediumsubprocess with shell=True
exec.shell-truebawbel_scanner-1.1.1/pyproject.toml: …# subprocess list args — correct, never shell=True ] severity = "medium" # ── Tool: flake…
- mediumeval / new Function used
exec.evalbawbel_scanner-1.1.1/scanner/engines/sandbox_engine.py: …, "AVE-2026-00004", "HIGH", 8.8), ("eval() code execution", "AVE-2026-00004", "HI…
Install Bawbel Scanner in Claude Code, Cursor or VS Code
claude mcp add bawbel-scanner -- uvx bawbel-scanner
What the publisher says
From the Bawbel Scanner repository's README, as published. We do not edit it. Read it on GitHub
Bawbel Scanner
<!-- mcp-name: io.github.bawbel/scanner -->
The only open-source scanner that produces OWASP AIVSS scores for MCP servers and skill files. Never executes code.
<!-- -->
Bawbel never executes your MCP servers.
pip install "bawbel-scanner[all]"
bawbel scan ./skills/ # scan skill files
bawbel ssc https://server # scan MCP server without starting itCommands
Why Bawbel
How it works
System overview
How a scan flows from your file to an AIVSS-scored finding:
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Bawbel Scanner: common questions
- Is Bawbel Scanner MCP server safe?
- Mostly: it is graded B (75/100). Read the Bawbel Scanner safety report
- How do I install Bawbel Scanner?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Bawbel Scanner need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Bawbel Scanner maintained?
- The last commit was 16 days ago (2026-09-12). The latest release is v1.1.1.
- What can I use instead of Bawbel Scanner?
- Servers from other publishers that do the same job: CodeInspectus MCP server, Prodcheck MCP server and prodlint MCP server. Compare all Bawbel Scanner alternatives.
Alternatives to Bawbel Scanner
Same job from other publishers: the closest match first, then the best rated.
- CodeInspectusLocal-first MCP security scanner and CLI for AI-generated applications.not reviewedGrowingC
- Prodcheck4,372 pre-production checks: security, performance, scale, integrations, post-launch.not reviewedGrowingA
- prodlintProduction readiness for vibe-coded apps. 52 checks for security, reliability, and performance.not reviewedGrowingA
- Security Headers Csp LintReads security headers and CSP line by line in your config file and names the lines that silently donot reviewedGrowingA
Black Duck Security ScannerAI-powered security scanning using Black Duck Signal for vulnerability detection.not reviewedGrowingA