Skip to main content

Shared scanning engine for Aevrin: models, OWASP MCP Top 10 mapping, scoring, and containerized scanner adapters. Imported by apps/api and packages/cli so findings never drift into different vocabularies.

Project description

Aevrin Scanner Core

The shared scanning engine used by the Aevrin API and CLI. It runs the same version-pinned scanner adapters, normalizes their output into one finding model, maps findings to the OWASP MCP Top 10, records per-stage coverage, and computes the report score.

This package is primarily an internal runtime dependency. Most users should install the aevrin CLI instead.

Development

uv sync
uv run ruff check .
uv run mypy src
uv run pytest

Scanner execution defaults to isolated Docker containers. The production API uses AEVRIN_EXECUTOR=subprocess with the same pinned binaries baked into its non-root container because Railway does not provide Docker-in-Docker.

Security model

  • Scanner subprocesses receive an allowlisted environment, not application or database credentials.
  • Remote MCP inspection accepts only public HTTPS endpoints and never executes submitted stdio commands.
  • A stage is marked incomplete when required tools fail; missing coverage is never presented as a clean scan.
  • Prompt injection through live tool responses (MCP08) remains explicitly outside static-scan coverage.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aevrin_scanner_core-0.1.8.tar.gz (29.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

aevrin_scanner_core-0.1.8-py3-none-any.whl (43.4 kB view details)

Uploaded Python 3

File details

Details for the file aevrin_scanner_core-0.1.8.tar.gz.

File metadata

  • Download URL: aevrin_scanner_core-0.1.8.tar.gz
  • Upload date:
  • Size: 29.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for aevrin_scanner_core-0.1.8.tar.gz
Algorithm Hash digest
SHA256 017ab4ffba1efab6b42d6036e9ad6a08b02e531aae8dc99f035c8cdf54dafebb
MD5 e19aebe11255ad2095f47125ddd3e2c9
BLAKE2b-256 a4faa1332443f507845d17b01778d47fc0dd3207adfa89ddba51ae52876f8909

See more details on using hashes here.

Provenance

The following attestation bundles were made for aevrin_scanner_core-0.1.8.tar.gz:

Publisher: publish.yml on aevrin-projects/aevrin-mcp-scanner

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file aevrin_scanner_core-0.1.8-py3-none-any.whl.

File metadata

File hashes

Hashes for aevrin_scanner_core-0.1.8-py3-none-any.whl
Algorithm Hash digest
SHA256 a0643be6a9a06e756268ec31edf8898b0ef4bc3a5f809a7fc2036853ee85082b
MD5 b7a7afef8642bdeef89bc868934f5534
BLAKE2b-256 87db2799d301fbc71a3f1ba073155a11c5f991a27cc9f8c43d928ed01a8bbbee

See more details on using hashes here.

Provenance

The following attestation bundles were made for aevrin_scanner_core-0.1.8-py3-none-any.whl:

Publisher: publish.yml on aevrin-projects/aevrin-mcp-scanner

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page