Physix Frontier · News Briefing Card (Hacker News · Oct 3, 2026)
Open-source SAST tool Rowan scans AI app code and model files
KEY FACTS
- Rowan scans source code and model files to detect vulnerabilities such as injection, SSRF, and secret leaks.
- The tool does not execute user code; it performs static analysis only.
- Installation requires Python 3.10+ and pipx, and the scanning engine is Opengrep.
- The rule library contains 590 rules spread across 48 YAML files.
- By default, scans do not call an LLM or upload code; only dependency queries go over the network.
KEY DATA
590Total rules
48YAML rule files
400Regex rules
190Taint rules
PHYSIX OBSERVATION
The security blind spots of AI applications are being filled by tooling. Rowan brings model files and agent toolchains into static scanning, hitting the territory traditional SAST cannot cover. But the Alpha stage plus the inherent false positives of static analysis mean users must treat it as a list of leads, not a verdict. Open source plus local execution is a plus for teams worried about code leaks.
Source: Hacker News report
Physix Frontier