Ansible Security Scanner

By Chris Peoples

View on Snapcraft.io
Version0.1.37
Revision3
Size17.9 MB
LicenseApache-2.0
Confinementstrict
Basecore24

Security scanner for Ansible: malicious code, RCE, secrets, supply chain


Static SAST for Ansible content: playbooks, roles, collections, task files, vars, and inventories.

Detects malicious code, remote code execution, command and template injection, hardcoded credentials, supply-chain risk, unauthorized cloud access, lateral movement, and reverse shells. Every finding ships with remediation guidance and maps to CWE, OWASP Top 10, OWASP ASVS, MITRE ATT&CK, NIST, and CIS.

Over 1,000 rules across 30+ detection categories, auto-discovered from YAML pattern plugins. Outputs SARIF, CycloneDX SBOM, GitLab SAST, JUnit, JSON, HTML, and Markdown.

CI-native and autofix-capable. Releases are Sigstore-signed with SLSA Build Level 3 provenance.

Update History

0.1.36 (2)0.1.37 (3)
20 Jul 2026, 20:45 UTC
0.1.36 (2)
16 Jul 2026, 17:00 UTC

Published16 Jul 2026, 16:41 UTC

Last updated20 Jul 2026, 20:16 UTC

First seen16 Jul 2026, 17:00 UTC