Mmcp.market

Bawbel Scanner MCP server

by bawbel·io.github.bawbel/scanner·v1.2.3·11 stars

Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.

B75/100grade B
What users say
No reviews yet
Be the first
Safety scan
B75/100

full report

Adoption
Growing

11 stars

Reviews

Write one

Nobody has reviewed Bawbel Scanner yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Bawbel Scanner tools

No tool declarations could be read from the package source. They show once the server is installed.

Public scan report

scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it

2 medium
  • Code scan56 source files scanned15/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 15 days ago15/15
  • Maintainer identityregistry namespace matches repository owner7/10

Findings (2)

  • mediumsubprocess with shell=Trueexec.shell-true
    bawbel_scanner-1.2.3/pyproject.toml: …# subprocess list args - correct, never shell=True ] severity = "medium" # ── Tool: flake…
  • mediumeval / new Function usedexec.eval
    bawbel_scanner-1.2.3/scanner/engines/sandbox_engine.py: …, "AVE-2026-00004", "HIGH", 5.9), ("eval() code execution", "AVE-2026-00004", "HI…
Overall 75/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Bawbel Scanner in Claude Code, Cursor or VS Code

claude mcp add scanner -- uvx bawbel-scanner
Add to Cursor

What the publisher says

From the Bawbel Scanner repository's README, as published. We do not edit it. Read it on GitHub

Bawbel Scanner

<!-- mcp-name: io.github.bawbel/scanner -->

The only open-source scanner that produces OWASP AIVSS scores for MCP servers and skill files. Never executes code.

<!-- -->

Bawbel never executes your MCP servers.

pip install "bawbel-scanner[all]"
bawbel scan ./skills/        # scan skill files
bawbel ssc https://server    # scan MCP server without starting it

Commands

Why Bawbel

How it works

System overview

How a scan flows from your file to an AIVSS-scored finding:

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Bawbel Scanner: common questions

Is Bawbel Scanner MCP server safe?
Mostly: it is graded B (75/100). Read the Bawbel Scanner safety report
How do I install Bawbel Scanner?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Bawbel Scanner need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Bawbel Scanner maintained?
The last commit was 16 days ago (2026-09-12). The latest release is v1.2.3.
What can I use instead of Bawbel Scanner?
Servers from other publishers that do the same job: CodeInspectus MCP server, Prodcheck MCP server and prodlint MCP server. Compare all Bawbel Scanner alternatives.

Alternatives to Bawbel Scanner

Same job from other publishers: the closest match first, then the best rated.

All Bawbel Scanner alternatives →
  • CodeInspectus
    Local-first MCP security scanner and CLI for AI-generated applications.
    C
  • Prodcheck
    4,372 pre-production checks: security, performance, scale, integrations, post-launch.
    A
  • prodlint
    Production readiness for vibe-coded apps. 52 checks for security, reliability, and performance.
    A
  • Security Headers Csp Lint
    Reads security headers and CSP line by line in your config file and names the lines that silently do
    A
  • Black Duck Security Scanner
    AI-powered security scanning using Black Duck Signal for vulnerability detection.
    A

More from bawbel →