Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
The only open-source scanner that produces OWASP AIVSS scores for MCP servers and skill files. Never executes code.
Bawbel never executes your MCP servers.
| Command | Description |
|---|---|
bawbel scan <path> | Scan a skill file or directory for AVE vulnerabilities. Supports --recursive, --format text|json|sarif, --fail-on-severity, --no-ignore, --watch |
bawbel report <path> | Scan a component and show a full remediation guide with fix guidance per finding |
bawbel creds <path> | Focused scan β hardcoded credentials and secret exposure only |
bawbel chain <path> | Focused scan β unsafe agent delegation chains only |
bawbel ssc <url> | Fetch and scan an MCP server-card for AVE vulnerabilities without starting the server |
bawbel scan-server-card <url> | Alias for ssc |
bawbel conform <target> | Score an MCP server manifest against the MCP specification (A+ to F grade) |
bawbel scan-conformance <target> | Alias for conform |
bawbel accept <id> <file> | Mark a finding as a false positive or accepted risk β inserts a justified suppression comment with reviewer and optional expiry |
bawbel pin <path> | Hash skill files and save to .bawbel-pins.json for rug pull detection |
bawbel check-pins <path> | Check skill files for drift against .bawbel-pins.json |
bawbel cp <path> | Alias for check-pins |
bawbel init | Initialise Bawbel Scanner in a project β generates .bawbelignore and bawbel.yml |
bawbel version | Show version and detection engine status |
| Bawbel | Snyk agent-scan | ClawGuard | Cisco DefenseClaw | |
|---|---|---|---|---|
| Executes MCP servers during scan | Never | Yes | No | Sandboxed |
| Open vulnerability database | Yes (48 records, public API) | No | No | No |
| OWASP AIVSS v0.8 scores | Yes | No | No | No |
| Toxic flow detection | Yes (12 chains) | No | No | No |
| Conformance grading (A+ to F) | Yes | No | No | No |
| Git-committed rug pull detection | Yes | Local only | No | No |
| Justified suppression with expiry | Yes | No | No | No |
| License | Apache 2.0 | Apache 2.0 | MIT | Proprietary |
How a scan flows from your file to an AIVSS-scored finding:
Six engines run in parallel. Results merge before toxic flow analysis:
Eight layers run automatically before a finding is reported:
| Layer | Mechanism | FP reduction |
|---|---|---|
| FP-1 | Code fence stripping | ~60% |
| FP-2 | Preceding-line negation context | ~15% |
| FP-3 | Confidence scoring (path, line context) | ~10% |
| FP-4 | LLM meta-analyzer (optional) | ~7% |
| FP-5a | Inline <!-- bawbel-ignore --> | per-line |
| FP-5b | Block suppression | per-section |
| FP-5c | .bawbelignore patterns | per-file |
| FP-6 | Justified suppression with audit trail | per-finding |
Every active finding carries a confidence field (0.0β1.0) that starts from the
AVE-class baseline and is adjusted by FP-2 through FP-4 before appearing in output.
confidence_band() maps it to "high" / "medium" / "low" for human display.
See Evidence Lifecycle for the full pipeline.
See Suppression Guide for full details.
A single fetch() call is a finding. A fetch() that retrieves credentials and then
sends them to an external endpoint is an attack chain β and the two findings together
are far more dangerous than either alone.
Bawbel is the only open-source scanner that detects these toxic flows: compound
attack sequences where two or more findings combine into a higher-severity threat.
After deduplication, every finding is mapped to a capability tag. Bawbel then checks
all pairs against 12 built-in chain definitions and raises a ToxicFlow when a
dangerous combination is found.
The toxic flow AIVSS (9.8) is higher than either individual finding (6.8), because the chain represents a complete, end-to-end exploit β not just a capability.
12 built-in chains:
| Flow | Capabilities required | AIVSS |
|---|---|---|
| Credential Exfiltration | credential-read + data-exfil | 9.8 |
| Remote Code Execution | code-exec + external-fetch | 9.7 |
| Supply Chain RCE | supply-chain + code-exec | 9.6 |
| Goal Override + Execution | goal-hijack + code-exec | 9.5 |
| Lateral Movement + Execution | lateral-movement + code-exec | 9.4 |
| Tool Poisoning + Exfiltration | tool-poison + data-exfil | 9.3 |
| Identity Spoof + Escalation | identity-spoof + privilege-escalation | 9.2 |
| Persistence + Exfiltration | persistence + data-exfil | 9.1 |
| Context Inject + Memory Write | context-inject + memory-write | 8.9 |
| Goal Override + Exfiltration | goal-hijack + data-exfil | 8.8 |
| Scope Expansion + Exfiltration | scope-expansion + data-exfil | 8.7 |
| Covert Channel + Persistence | covert-channel + persistence | 8.6 |
Toxic flow in JSON output:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/bawbel-scanner-2)<a href="https://allmcps.com/mcp/bawbel-scanner-2"><img src="https://allmcps.com/api/badge/bawbel-scanner-2?style=directory" alt="Bawbel Scanner on AllMCPs" /></a>