Skip to main content

Shared scanning engine for Aevrin: models, OWASP MCP Top 10 mapping, scoring, and containerized scanner adapters. Imported by apps/api and packages/cli so findings never drift into different vocabularies.

Project description

Aevrin Scanner Core

The shared scanning engine used by the Aevrin API and CLI. It runs the same version-pinned scanner adapters, normalizes their output into one finding model, maps findings to the OWASP MCP Top 10, records per-stage coverage, and computes the report score.

This package is primarily an internal runtime dependency. Most users should install the aevrin CLI instead.

Development

uv sync
uv run ruff check .
uv run mypy src
uv run pytest

Scanner execution defaults to isolated Docker containers. The production API uses AEVRIN_EXECUTOR=subprocess with the same pinned binaries baked into its non-root container because Railway does not provide Docker-in-Docker.

Security model

  • Scanner subprocesses receive an allowlisted environment, not application or database credentials.
  • Remote MCP inspection accepts only public HTTPS endpoints and never executes submitted stdio commands.
  • A stage is marked incomplete when required tools fail; missing coverage is never presented as a clean scan.
  • Prompt injection through live tool responses (MCP08) remains explicitly outside static-scan coverage.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aevrin_scanner_core-0.1.7.tar.gz (29.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

aevrin_scanner_core-0.1.7-py3-none-any.whl (43.0 kB view details)

Uploaded Python 3

File details

Details for the file aevrin_scanner_core-0.1.7.tar.gz.

File metadata

  • Download URL: aevrin_scanner_core-0.1.7.tar.gz
  • Upload date:
  • Size: 29.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for aevrin_scanner_core-0.1.7.tar.gz
Algorithm Hash digest
SHA256 6dd6d4a4bb82215f2c155e97f72e450dc3adfc67dd074c9fd2bb46d2440bd016
MD5 868e21a53abb33b3395e4cc8951ef183
BLAKE2b-256 47b6259df477834aad7a126e2cece77bc8f4870e30c4711c5de885ca2d2459b7

See more details on using hashes here.

Provenance

The following attestation bundles were made for aevrin_scanner_core-0.1.7.tar.gz:

Publisher: publish.yml on aevrin-projects/aevrin-mcp-scanner

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file aevrin_scanner_core-0.1.7-py3-none-any.whl.

File metadata

File hashes

Hashes for aevrin_scanner_core-0.1.7-py3-none-any.whl
Algorithm Hash digest
SHA256 82085fd3256c0d7e2acfd5d4c6caef0becb4be966dc8585ac7e4bc1f564faed7
MD5 2eb7fac9ab2e722bb772d3402117adea
BLAKE2b-256 d4bec10c0faf230348099a1f3504608376dda2953f97558b2556f7c5ae602742

See more details on using hashes here.

Provenance

The following attestation bundles were made for aevrin_scanner_core-0.1.7-py3-none-any.whl:

Publisher: publish.yml on aevrin-projects/aevrin-mcp-scanner

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page