Skip to content

Community CLI

bastyn-scan is Bastyn’s open-source, Apache-2.0-licensed static analysis CLI for AI agent, MCP, and tool-enabled application code. It ships as a single Rust binary — no interpreter, no account, no LLM/API key — and checks for unsafe autonomous actions, excessive agent/MCP tool permissions, missing control signals, and dependency CVEs.

This is a separate, standalone tool from the certification API documented elsewhere in these docs. It’s the fastest way to scan a repository locally or in CI before it ever reaches Bastyn’s platform.

Install

Terminal window
cargo install bastyn

Verify the install:

Terminal window
bastyn --version

Run a scan

Terminal window
bastyn scan

A scan reports defects (provable issues, such as model output executed as code, or a hardcoded API key) separately from observations (missing controls that can’t be substantiated as a bug). Only defects can fail the build; pass --show-observations to also print observations, and --offline to skip the OSV dependency lookup.

GitHub Action

The scanner is also published as a GitHub Action, BASTYN Community - Instant AI Agent Security & Assurance scan, on the GitHub Marketplace:

- uses: BASTYN-labs/bastyn-scan@v0.1.5
with:
path: .
fail-on: high

Source and license

bastyn-scan is developed in the open at github.com/BASTYN-labs/bastyn-scan under the Apache-2.0 license. Issues and pull requests are welcome there — see the repo’s CONTRIBUTING.md.