{"slug": "show-hn-rowan-an-open-source-sast-scanner-for-ai-apps-code-models-mcp", "title": "Show HN: Rowan, an open-source SAST scanner for AI apps (code, models, MCP)\"", "summary": "Hedgerow-dev released Rowan, an open-source static application security testing (SAST) scanner for AI and ML projects, installable via `pipx install \"rowan-sast[js-crossfile]\"` on Python 3.10+. Rowan scans source code and model files for injection, unsafe deserialization, SSRF, leaked secrets, risky agent tools and unsafe model loading, and ships a rule catalog of 590 rules across 48 YAML files (400 regex rules and 190 Opengrep taint rules). The tool is in alpha, never runs the scanned code or calls an LLM, and its only network calls are dependency lookups to OSV.", "body_md": "**Find security issues in your code and AI/ML projects, with evidence you can review.**\n\nRowan reads your project's source code and model files and reports likely vulnerabilities: injection, unsafe deserialization, SSRF, leaked secrets, risky agent tools, unsafe model loading and more. It never runs your code.\n\n**Alpha.** Treat every finding as a lead to check, not a confirmed bug.\nA clean report does not prove a project is secure.\n\nYou need **Python 3.10+** and [pipx](https://pipx.pypa.io), which installs\ncommand-line tools into their own environment (on macOS: `brew install pipx`,\nthen `pipx ensurepath` and open a new terminal).\n\n**1. Install Rowan:**\n\n```\npipx install \"rowan-sast[js-crossfile]\"\n```\n\nAlready use uv? `uv tool install \"rowan-sast[js-crossfile]\"` works too. A plain\n`pip install` fails on Homebrew Python by design; see\n[getting started](https://github.com/hedgerow-dev/rowan/blob/main/docs/getting-started.md) for a virtual-environment install.\n\n**2. Install the scan engine** ([Opengrep](https://github.com/opengrep/opengrep)) and check it:\n\n```\nrowan install-engine\nexport PATH=\"$HOME/.local/bin:$PATH\"\nrowan self-test\n```\n\n`self-test` should print `[OK]` three times.\n\n**3. Scan a project:**\n\n```\nrowan scan /path/to/your-project\n```\n\nWindows, troubleshooting and more detail: [getting started](https://github.com/hedgerow-dev/rowan/blob/main/docs/getting-started.md).\n\nPaste this into Claude Code, Codex, Cursor or any agent that can run terminal commands, with your project open:\n\n```\nInstall Rowan and scan this project for security issues.\n1. Install it in its own folder (not inside this project) by following\n   https://github.com/hedgerow-dev/rowan/blob/main/docs/getting-started.md\n2. Run `rowan self-test`. If the engine is not [OK], stop and tell me.\n3. Run: rowan scan <this project's absolute path> --no-project-config\n   --no-sca --audit -f json -o <a folder outside this project>/rowan-report.json\n4. If summary.degraded is true, tell me the scan is incomplete and why.\n5. List the High and Critical findings with file:line links. For each one,\n   say whether you checked the code or it is still just a lead.\n6. Do not change any code in this project.\n```\n\n`--no-sca` keeps this first scan offline. Drop it to also check your\ndependencies for known CVEs (this sends package names and versions to OSV).\n\n```\nrowan scan PATH                                  # readable report\nrowan scan PATH --audit                          # include low-severity findings\nrowan scan PATH -f json -o report.json           # save a report (also: html, sarif)\nrowan scan PATH --ci --severity high             # CI: exit 1 on high/critical findings\nrowan scan PATH --write-baseline base.json       # record today's findings...\nrowan scan PATH --ci --baseline base.json        # ...then report only new ones\n```\n\nWith `--ci`, exit code **0** means no findings, **1** means findings, and **2**\nmeans the scan was incomplete. Reports can contain source code and secrets:\nreview them before sharing.\n\n| Area | Coverage | \n|---|---|\n| Source code | Injection, unsafe deserialization, path traversal, SSRF, XSS, secrets | \n| AI/ML apps | Model loading, agent tools, LLM output handling, prompt files, MCP config | \n| Dataflow | Within-file through Opengrep; cross-file for Python and JS/TS, limited for Go | \n| Dependencies | Known CVEs, reachability hints, CycloneDX SBOM and OpenVEX output | \n| Model files | Pickle, PyTorch, GGUF, SafeTensors, Keras, ONNX, TensorFlow, numpy, joblib (via [Hayward](https://github.com/hedgerow-dev/hayward) ) | \n\nPython and JS/TS get the deepest analysis. Java, Kotlin and C# get within-file dataflow. Ruby, PHP and Rust get limited pattern checks. The report lists what it could not analyze.\n\nThe rule catalog has **590 rules across 48 YAML files**.\nThat is 400 regex rules and 190 taint rules (Opengrep). See the [rule catalog](https://github.com/hedgerow-dev/rowan/blob/main/docs/rules.md).\n\n`rowan scan` never calls an LLM or uploads your code. Its only network calls\nare dependency lookups (OSV and FIRST EPSS), which `--no-sca` turns off.\nThe experimental `rowan hunt` command does send code to the LLM you configure:\nsee the [usage guide](https://github.com/hedgerow-dev/rowan/blob/main/docs/usage.md).\n\n- [Getting started](https://github.com/hedgerow-dev/rowan/blob/main/docs/getting-started.md) : install, first scan, MCP setup, troubleshooting\n- [Capabilities](https://github.com/hedgerow-dev/rowan/blob/main/docs/capabilities.md) : what Rowan finds, how it compares, measured results\n- [Usage guide](https://github.com/hedgerow-dev/rowan/blob/main/docs/usage.md) : every option, configuration, baselines, CI and GitHub Action\n- [Contributing](https://github.com/hedgerow-dev/rowan/blob/main/CONTRIBUTING.md) and[architecture](https://github.com/hedgerow-dev/rowan/blob/main/ARCHITECTURE.md)\n- [Security policy](https://github.com/hedgerow-dev/rowan/blob/main/SECURITY.md) : report a vulnerability in Rowan privately\n\n[MIT](https://github.com/hedgerow-dev/rowan/blob/main/LICENSE). Opengrep is a separate LGPL-2.1 engine and is not bundled.", "url": "https://wpnews.pro/news/show-hn-rowan-an-open-source-sast-scanner-for-ai-apps-code-models-mcp", "canonical_source": "https://github.com/hedgerow-dev/rowan", "published_at": "2026-10-03 05:29:44+00:00", "updated_at": "2026-10-03 05:36:11.402300+00:00", "lang": "en", "topics": ["ai-safety", "ai-tools", "developer-tools", "ai-agents", "ai-infrastructure"], "entities": ["Rowan", "Hedgerow-dev", "Opengrep", "Hayward", "OSV", "Claude Code", "Codex", "Cursor"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/show-hn-rowan-an-open-source-sast-scanner-for-ai-apps-code-models-mcp", "markdown": "https://wpnews.pro/news/show-hn-rowan-an-open-source-sast-scanner-for-ai-apps-code-models-mcp.md", "text": "https://wpnews.pro/news/show-hn-rowan-an-open-source-sast-scanner-for-ai-apps-code-models-mcp.txt", "jsonld": "https://wpnews.pro/news/show-hn-rowan-an-open-source-sast-scanner-for-ai-apps-code-models-mcp.jsonld"}}