Skip to main content

Shared scanning engine for Aevrin: models, OWASP MCP Top 10 mapping, scoring, and containerized scanner adapters. Imported by apps/api and packages/cli so findings never drift into different vocabularies.

Project description

Aevrin Scanner Core

The shared scanning engine used by the Aevrin API and CLI. It runs the same version-pinned scanner adapters, normalizes their output into one finding model, maps findings to the OWASP MCP Top 10, records per-stage coverage, and computes the report score.

This package is primarily an internal runtime dependency. Most users should install the aevrin CLI instead.

Development

uv sync
uv run ruff check .
uv run mypy src
uv run pytest

Scanner execution defaults to isolated Docker containers. The production API uses AEVRIN_EXECUTOR=subprocess with the same pinned binaries baked into its non-root container because Railway does not provide Docker-in-Docker.

Security model

  • Scanner subprocesses receive an allowlisted environment, not application or database credentials.
  • Remote MCP inspection accepts only public HTTPS endpoints and never executes submitted stdio commands.
  • A stage is marked incomplete when required tools fail; missing coverage is never presented as a clean scan.
  • Prompt injection through live tool responses (MCP08) remains explicitly outside static-scan coverage.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aevrin_scanner_core-0.1.9.tar.gz (29.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

aevrin_scanner_core-0.1.9-py3-none-any.whl (43.4 kB view details)

Uploaded Python 3

File details

Details for the file aevrin_scanner_core-0.1.9.tar.gz.

File metadata

  • Download URL: aevrin_scanner_core-0.1.9.tar.gz
  • Upload date:
  • Size: 29.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for aevrin_scanner_core-0.1.9.tar.gz
Algorithm Hash digest
SHA256 f2f2cdafc224ab0d2ad460f77593cca14a3911ea9f7b11e85226e44471f68064
MD5 482575c3cfe798152ec217fe7eb68f3d
BLAKE2b-256 97fb84c69c279df5d107ccafae1f9948f28aece059f2dda336eb881acc98d2e8

See more details on using hashes here.

Provenance

The following attestation bundles were made for aevrin_scanner_core-0.1.9.tar.gz:

Publisher: publish.yml on aevrin-projects/aevrin-mcp-scanner

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file aevrin_scanner_core-0.1.9-py3-none-any.whl.

File metadata

File hashes

Hashes for aevrin_scanner_core-0.1.9-py3-none-any.whl
Algorithm Hash digest
SHA256 b90380a832a32c631f412412170b0233a34d1881dd35f9822609a4b77c5f44e5
MD5 a01e2ad18a2ff449f606ecb91340be42
BLAKE2b-256 a7d4350c51ef6c6945b930e3edcbe012b2b76eb10c71b321196f6c16d8c7b278

See more details on using hashes here.

Provenance

The following attestation bundles were made for aevrin_scanner_core-0.1.9-py3-none-any.whl:

Publisher: publish.yml on aevrin-projects/aevrin-mcp-scanner

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page