Ansible Security Scanner

By Chris Peoples

View on Snapcraft.io
Version0.1.41
Revision7
Size17.5 MB
LicenseApache-2.0
Confinementstrict
Basecore24

Security scanner for Ansible: malicious code, RCE, secrets, supply chain


Static SAST for Ansible content: playbooks, roles, collections, task files, vars, and inventories.

Detects malicious code, remote code execution, command and template injection, hardcoded credentials, supply-chain risk, unauthorized cloud access, lateral movement, and reverse shells. Every finding ships with remediation guidance and maps to CWE, OWASP Top 10, OWASP ASVS, MITRE ATT&CK, NIST, and CIS.

Over 1,000 rules across 30+ detection categories, auto-discovered from YAML pattern plugins. Outputs SARIF, CycloneDX SBOM, GitLab SAST, JUnit, JSON, HTML, and Markdown.

CI-native and autofix-capable. Releases are Sigstore-signed with SLSA Build Level 3 provenance.

Update History

0.1.40 (6)0.1.41 (7)
25 Aug 2026, 13:45 UTC
0.1.39 (5)0.1.40 (6)
25 Aug 2026, 02:30 UTC
0.1.38 (4)0.1.39 (5)
3 Aug 2026, 21:45 UTC
0.1.37 (3)0.1.38 (4)
1 Aug 2026, 18:30 UTC
0.1.36 (2)0.1.37 (3)
20 Jul 2026, 20:45 UTC
0.1.36 (2)
16 Jul 2026, 17:00 UTC

Published16 Jul 2026, 16:41 UTC

Last updated25 Aug 2026, 13:28 UTC

First seen16 Jul 2026, 17:00 UTC