Rowan: evidence-led security scanning for AI applications

Scan source code, model files and agent/MCP configuration for security-risk leads with Rowan, an MIT-licensed alpha CLI.

LinkLoot access
Free
Provider costs
Unknown
The useful part1 min read

What you get from it

Automated assessment

Practical testing not documented.

Value
A focused free scanning option for AI codebases.
Ease
Setup requires developer tooling.
Safety
Treat results as leads, not a security verdict.
Privacy
Offline scanning is documented, with optional external lookups.
Maintenance outlook
Too new to judge long-term upkeep.

LinkLoot assessment · not a user rating.

Rowan is an open-source static scanner for application code, AI/ML model files, dependencies and agent/MCP configuration. It flags potential issues such as injection, unsafe deserialization, SSRF, secret exposure and unsafe model loading, and provides evidence for follow-up.

Setup: Python 3.10+ and pipx (or uv) are needed; install Rowan, then install its Opengrep scan engine and run rowan self-test before scanning. The getting-started guide covers platform-specific installation.

Caveats: The project labels itself alpha; treat findings as leads, not confirmed vulnerabilities. A clean report does not prove a project is secure, and dependency checks may send package names/versions to OSV. No hands-on testing is claimed.

Sources: official repository and setup guide.

Community

Discussion

Share practical experience, questions, or warnings with the community.

0

Sign in to join the discussion and vote on comments.

No comments yet. Start the discussion.
Keep exploring

More from this topic

More in Tools & Apps