Analyze JavaScript source code to detect obfuscation patterns like webpack, JSFuck, or eval-based loaders, and output unpack hints with deobfuscation strategy.
Bawbel MCP Server lets any agent scan MCP servers and skill files for security vulnerabilities mid-conversation. Seven tools covering server-card scanning, conformance scoring, rug pull detection, and AVE threat intelligence queries. Powered by the AVE standard with OWASP MCP Top 10 mapping on every finding. Free, Apache 2.0, no API key required.
Scan text content to identify AVE security vulnerabilities in agentic AI components. Get findings with severity scores, OWASP categories, and remediation guidance.
Scan skill files for hardcoded credentials including API keys, tokens, passwords, and private keys. Detect secrets before adding a file to your agent configuration.
Retrieve the complete AVE record for a given vulnerability ID, including title, description, AIVSS score, behavioral fingerprint, indicators of compromise, OWASP MCP mapping, and remediation steps.
Mark a security finding as a false positive or accepted risk with a documented reason and reviewer. Write a structured suppression comment into the file, with optional expiry for accepted risks.
Execute arbitrary Bazel queries to retrieve dependency information and build graph data. Supports multiple output formats such as label, build, xml, and graph.
Map a generated code location (line and column) back to the original source using source maps, enabling debugging of bundled or transpiled code like TypeScript, Babel, webpack, or esbuild.