Rowan v0.3.0 (alpha)
First public alpha of Rowan: a static security scanner for AI applications. It scans source code, model files, dependencies and agent/MCP configuration, says what evidence backs each finding, and reports what it could not analyse.
Install
pipx install rowan-sast # or: uv tool install rowan-sast (macOS: brew install pipx first)
rowan install-engine # Opengrep v1.29.0, checked against a built-in SHA-256
rowan scan /path/to/your-projectA bare pip install is refused by Homebrew Python; use pipx, uv, or a virtual environment.
Highlights
- Opengrep dataflow within each file, plus cross-file analysis for Python and JS/TS (limited for Go) and stored-then-read flows through ORMs and vector stores.
- AI and agent rules for Python, JS/TS, Java and Go: agent tools, LLM output handling, MCP servers, model loading, guardrails.
- Model-file scanning via Hayward 1.2.4.
- Text, JSON, HTML and SARIF reports; CI exit codes, baselines, a GitHub Action and an MCP server for coding agents.
Measured (details and caveats in the linked write-ups)
- RealVuln, 63 Python apps: F2 33.0 against SonarQube 14.7 and Semgrep CE 7.5 on the same repositories; precision is below Snyk's.
- Model files on quickset: 26/26 malicious files detected, 0/225 false positives, every file read.
Alpha: treat findings as leads to check, not confirmed bugs. A clean report does not prove a project is secure. See capabilities and known limits.
The GitHub Action example in the docs needs permissions: security-events: write to upload SARIF; the usage guide on main has the corrected example.