mcpbeat Sign in

Bawbel Scanner MCP Server

local only

Bawbel Scanner runs on your own machine — the client starts it, so there is no endpoint to ping. 79 installs a week from pypi. Last commit 23 May 2026.

Scan MCP servers and skill files for AVE vulnerabilities. Conformance scoring and threat intel.

Installs per day peak 36 · avg 14 · +1% w/w
a month agotoday
79
Installs / week
pypi · bawbel-mcp
1
Stars
0 open issues
23 May 2026
Last commit
0 releases in 90 days
Apache-2.0
License
Python

What the code does

We read the source, 20 min ago · rules 3dff92dd89df

A tool parameter reaches a dangerous call

A value the model can set ends up inside a file or shell call. That is not a flaw by itself — for a terminal server it is the job — but it is where things go wrong when it is not.

A tool parameter reaches a dangerous call check_pins.path → bawbel_mcp/server.py:736
        result = subprocess.run(  # nosec B603  # noqa: S603
Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

        result = subprocess.run(  # nosec B603  # noqa: S603

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

A tool parameter here reaches a dangerous call

That is not a flaw by itself — but it is where things go wrong when it is not the job. We re-read this code on every release. Watch it and you hear from us the day another one appears.

Three servers free · no card

Connect this server

This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.

run in your terminal
claude mcp add bawbel-mcp -- uvx bawbel-mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "bawbel-mcp": {
      "args": [
        "bawbel-mcp"
      ],
      "command": "uvx"
    }
  }
}
~/.codex/config.toml
[mcp_servers.bawbel-mcp]
command = "uvx"
args = ["bawbel-mcp"]
.cursor/mcp.json
{
  "mcpServers": {
    "bawbel-mcp": {
      "args": [
        "bawbel-mcp"
      ],
      "command": "uvx"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "bawbel-mcp": {
      "args": [
        "bawbel-mcp"
      ],
      "command": "uvx"
    }
  }
}

Alternatives to Bawbel Scanner

same job, measured the same way
Bawbel Scanner
by bawbel

Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.

176 installs/wk local only
Bawbel Scanner
by bawbel

Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.

local only
Base Security Scanner MCP
by lordbasilaiassistant-sudo

MCP server to scan smart contracts on Base for honeypots, rug pulls, and vulnerabilities.

255 installs/wk local only
Inkog
by inkog-io

Security co-pilot for AI agents. Scan for vulnerabilities, audit MCP servers, verify governance.

228 installs/wk local only
MCPAmpel - MCP Security Scanner
by diemoeve

Scan installed MCP servers for security vulnerabilities with 16 detection engines.

69 installs/wk local only
Vulnicheck
by andrasfe

HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.

local only
Snyk API & Web MCP Server
by snyk

MCP server for Snyk API & Web — DAST scanning, findings management, and vulnerability triage

96 installs/wk local only
CodeVulnerability
by evozim

OWASP threat scanner auditing codebases for safety leaks.

answering

Bawbel Scanner — questions

Answers built from our own checks of this server.

Why is there no uptime for Bawbel Scanner?
Bawbel Scanner runs on your own machine over stdio — there is no network address to reach, so uptime cannot be measured for it by anyone. What can be measured is adoption: the pypi package bawbel-mcp was installed 79 times last week.
How do I connect Bawbel Scanner?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It runs locally, so the command pulls bawbel-mcp straight from pypi; nothing to host, nothing to sign up for.
How many people use Bawbel Scanner?
The pypi package bawbel-mcp was installed 79 times in the last week. Week over week that is +1%. We show installs rather than GitHub stars on purpose: a star is a bookmark, an install is someone actually running it.
Is Bawbel Scanner open source?
Yes — it is published under the Apache-2.0 licence, written in Python and 1 stars on GitHub. The source link is on this page, so you can read exactly what it does with your data before you connect it.