Community CLI
bastyn-scan is Bastyn’s open-source, Apache-2.0-licensed static analysis CLI for AI agent, MCP, and tool-enabled application code. It ships as a single Rust binary — no interpreter, no account, no LLM/API key — and checks for unsafe autonomous actions, excessive agent/MCP tool permissions, missing control signals, and dependency CVEs.
This is a separate, standalone tool from the certification API documented elsewhere in these docs. It’s the fastest way to scan a repository locally or in CI before it ever reaches Bastyn’s platform.
Install
cargo install bastynbrew install bastyn-labs/tap/bastyncurl -fsSL https://raw.githubusercontent.com/BASTYN-labs/bastyn-scan/main/install.sh | shVerify the install:
bastyn --versionRun a scan
bastyn scanA scan reports defects (provable issues, such as model output executed as code, or a hardcoded API key) separately from observations (missing controls that can’t be substantiated as a bug). Only defects can fail the build; pass --show-observations to also print observations, and --offline to skip the OSV dependency lookup.
GitHub Action
The scanner is also published as a GitHub Action, BASTYN Community - Instant AI Agent Security & Assurance scan, on the GitHub Marketplace:
- uses: BASTYN-labs/bastyn-scan@v0.1.5with: path: . fail-on: highSource and license
bastyn-scan is developed in the open at github.com/BASTYN-labs/bastyn-scan under the Apache-2.0 license. Issues and pull requests are welcome there — see the repo’s CONTRIBUTING.md.