Show HN: Rowan, an open-source SAST scanner for AI apps (code, models, MCP)" Hedgerow-dev released Rowan, an open-source static application security testing (SAST) scanner for AI and ML projects, installable via `pipx install "rowan-sast[js-crossfile]"` on Python 3.10+. Rowan scans source code and model files for injection, unsafe deserialization, SSRF, leaked secrets, risky agent tools and unsafe model loading, and ships a rule catalog of 590 rules across 48 YAML files (400 regex rules and 190 Opengrep taint rules). The tool is in alpha, never runs the scanned code or calls an LLM, and its only network calls are dependency lookups to OSV. Find security issues in your code and AI/ML projects, with evidence you can review. Rowan reads your project's source code and model files and reports likely vulnerabilities: injection, unsafe deserialization, SSRF, leaked secrets, risky agent tools, unsafe model loading and more. It never runs your code. Alpha. Treat every finding as a lead to check, not a confirmed bug. A clean report does not prove a project is secure. You need Python 3.10+ and pipx https://pipx.pypa.io , which installs command-line tools into their own environment on macOS: brew install pipx , then pipx ensurepath and open a new terminal . 1. Install Rowan: pipx install "rowan-sast js-crossfile " Already use uv? uv tool install "rowan-sast js-crossfile " works too. A plain pip install fails on Homebrew Python by design; see getting started https://github.com/hedgerow-dev/rowan/blob/main/docs/getting-started.md for a virtual-environment install. 2. Install the scan engine Opengrep https://github.com/opengrep/opengrep and check it: rowan install-engine export PATH="$HOME/.local/bin:$PATH" rowan self-test self-test should print OK three times. 3. Scan a project: rowan scan /path/to/your-project Windows, troubleshooting and more detail: getting started https://github.com/hedgerow-dev/rowan/blob/main/docs/getting-started.md . Paste this into Claude Code, Codex, Cursor or any agent that can run terminal commands, with your project open: Install Rowan and scan this project for security issues. 1. Install it in its own folder not inside this project by following https://github.com/hedgerow-dev/rowan/blob/main/docs/getting-started.md 2. Run rowan self-test . If the engine is not OK , stop and tell me. 3. Run: rowan scan