Broken Access Control Scanner
Broken Access Control Scanner is an AI command line tool to detect broken access control vulnerabilities in source code using Anthropic's Claude AI.
Installation
Releases are made available on PyPi.
The recommended installation method is via pip:
pip install broken-access-control-scanner
Usage
python -m broken_access_control_scanner <source_file> --data-model "<data_model_description>"
Requires ANTHROPIC_API_KEY environment variable to be set.
Arguments
source_file: Path to a source code file containing endpoints--data-model,-d: Description of the data model and context for the endpoints (required)--model,-m: Anthropic model to use (default:claude-sonnet-4-20250514)
Example
python -m broken_access_control_scanner api.py \
--data-model "REST API with User and Document models. Users should only access their own profiles."
Output Example
┏━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ Endpoint ┃ Severity ┃ Description ┃
┡━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩
│ /api/users/{id}/profile │ NONE │ Proper authorization check │
│ /api/documents/{id} │ CRITICAL │ No authentication or auth check │
└───────────────────────────┴────────────┴──────────────────────────────────┘
Severity Levels
- NONE: No access control issues found
- LOW: Minor issues, unlikely to be exploitable
- MEDIUM: Access control weakness that could be exploited under certain conditions
- HIGH: Clear access control vulnerability that can likely be exploited
- CRITICAL: Severe access control vulnerability with high impact, easily exploitable
Metadata
Release files for broken-access-control-scanner 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| broken_access_control_scanner-0.1.0.tar.gz | 17.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| broken_access_control_scanner-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 35.5 kB
Release files / broken_access_control_scanner-0.1.0.tar.gz
| Download URL | broken_access_control_scanner-0.1.0.tar.gz |
|---|---|
| Size | 17.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b184c41dbcdb098c43987211a9872ee4509956386ef9254b5827aad7a18cfa5c
|
|
BLAKE2b-256 checksum How to use checksums |
f0395286f90f7f16215d4d0c617f0a1de7ee5b69d7180189f711c2e4c55defbd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 9, 2026.
Transparency logRelease files / broken_access_control_scanner-0.1.0-py3-none-any.whl
| Download URL | broken_access_control_scanner-0.1.0-py3-none-any.whl |
|---|---|
| Size | 18.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1b928fe711f61cddab364a68b1f2412543b66ba17a676b4fe61e8171beb03dfa
|
|
BLAKE2b-256 checksum How to use checksums |
6911686535a4819d95476ddfc0d259306d577392c4043332bfed54f8947b425c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 9, 2026.
Transparency log