Skip to main content

Broken Access Control Scanner

Broken Access Control Scanner is an AI command line tool to detect broken access control vulnerabilities in source code using Anthropic's Claude AI.

Installation

Releases are made available on PyPi. The recommended installation method is via pip:

pip install broken-access-control-scanner

Usage

python -m broken_access_control_scanner <source_file> --data-model "<data_model_description>"

Requires ANTHROPIC_API_KEY environment variable to be set.

Arguments

  • source_file: Path to a source code file containing endpoints
  • --data-model, -d: Description of the data model and context for the endpoints (required)
  • --model, -m: Anthropic model to use (default: claude-sonnet-4-20250514)

Example

python -m broken_access_control_scanner api.py \
    --data-model "REST API with User and Document models. Users should only access their own profiles."

Output Example

┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ Endpoint                  ┃  Severity  ┃ Description                      ┃
┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩
│ /api/users/{id}/profile   │    NONE    │ Proper authorization check       │
│ /api/documents/{id}       │  CRITICAL  │ No authentication or auth check  │
└───────────────────────────┴────────────┴──────────────────────────────────┘

Severity Levels

  • NONE: No access control issues found
  • LOW: Minor issues, unlikely to be exploitable
  • MEDIUM: Access control weakness that could be exploited under certain conditions
  • HIGH: Clear access control vulnerability that can likely be exploited
  • CRITICAL: Severe access control vulnerability with high impact, easily exploitable

Metadata

Release files for broken-access-control-scanner 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for broken-access-control-scanner 0.1.0
File Size Uploaded
broken_access_control_scanner-0.1.0.tar.gz 17.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for broken-access-control-scanner 0.1.0
File Interpreter ABI Platform
broken_access_control_scanner-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 35.5 kB

Release files / broken_access_control_scanner-0.1.0.tar.gz

Download URL broken_access_control_scanner-0.1.0.tar.gz
Size 17.1 kB
Tags Source
SHA-256 checksum
How to use checksums
b184c41dbcdb098c43987211a9872ee4509956386ef9254b5827aad7a18cfa5c
BLAKE2b-256 checksum
How to use checksums
f0395286f90f7f16215d4d0c617f0a1de7ee5b69d7180189f711c2e4c55defbd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 9, 2026.

Transparency log

Release files / broken_access_control_scanner-0.1.0-py3-none-any.whl

Download URL broken_access_control_scanner-0.1.0-py3-none-any.whl
Size 18.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1b928fe711f61cddab364a68b1f2412543b66ba17a676b4fe61e8171beb03dfa
BLAKE2b-256 checksum
How to use checksums
6911686535a4819d95476ddfc0d259306d577392c4043332bfed54f8947b425c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Feb 9, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

0.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page