Rowan Introduces Static Security Scanning for AI Applications
Summary
Rowan is an alpha command-line static security scanner for software and AI/ML projects. It reads source code, model files, dependencies, prompt files, and agent or MCP configuration to report likely issues such as injection, unsafe deserialization, SSRF, leaked secrets, risky agent tools, unsafe model loading, and unsafe handling of LLM output. The tool does not execute the scanned code, and every finding includes evidence for review, but the project warns that findings are leads rather than confirmed vulnerabilities and that a clean report does not prove a project is secure. Rowan requires Python 3.10+ and can be installed with pipx or uv; users must separately install and test the Opengrep scan engine. It supports readable, JSON, HTML, and SARIF reports, CI thresholds, and baselines for identifying new findings. Dependency scanning can check known CVEs and produce CycloneDX SBOM and OpenVEX output, but it sends package names and versions to OSV and can be disabled with --no-sca. The scanner covers model formats including Pickle, PyTorch, GGUF, SafeTensors, Keras, ONNX, TensorFlow, NumPy, and joblib through Hayward. Python and JavaScript/TypeScript receive the deepest cross-file analysis, while other languages have narrower coverage. Its catalog contains 590 rules across 48 YAML files, including 400 regex rules and 190 Opengrep taint rules. Rowan says ordinary scans do not call an LLM or upload project code; an experimental hunt command is the exception because it sends code to a configured LLM. Reports may contain source code and secrets, so they should be reviewed before sharing. The project is distributed under the MIT license, while the separate Opengrep engine is LGPL-2.1 and is not bundled.