Rowan: evidence-led security scanning for AI applications
Scan source code, model files and agent/MCP configuration for security-risk leads with Rowan, an MIT-licensed alpha CLI.
- LinkLoot access
- Free
- Provider costs
- Unknown
What you get from it
Practical testing not documented.
LinkLoot assessment · not a user rating.
Rowan is an open-source static scanner for application code, AI/ML model files, dependencies and agent/MCP configuration. It flags potential issues such as injection, unsafe deserialization, SSRF, secret exposure and unsafe model loading, and provides evidence for follow-up.
Setup: Python 3.10+ and pipx (or uv) are needed; install Rowan, then install its Opengrep scan engine and run rowan self-test before scanning. The getting-started guide covers platform-specific installation.
Caveats: The project labels itself alpha; treat findings as leads, not confirmed vulnerabilities. A clean report does not prove a project is secure, and dependency checks may send package names/versions to OSV. No hands-on testing is claimed.
Sources: official repository and setup guide.
Discussion
Share practical experience, questions, or warnings with the community.
Sign in to join the discussion and vote on comments.
Sign in