Updated Sep 22, 2026

Static Code Analysis

Find shell injection in a Python folder

Python source in, JSON security findings out.

Agent

overview

What bandit does

Bandit reads a connected folder of Python files, parses each file into an AST, and writes a JSON report of plugin hits.

A Managed-fleet smoke on a two-line script that calls subprocess with shell=True returned B602, the shell-injection check, in that JSON report.

Connect the folder that holds the .py files. A bare text file is not scanned as Python.

source github.com/PyCQA/bandit

use cases

Where bandit fits

Scan application source

Point Bandit at the folder that contains the Python modules you ship.

Catch shell invocation

Surface subprocess calls that pass shell=True before that code runs.

Hand JSON to triage

Keep the plugin id, filename, and issue text in one report for a later node.

reference

bandit inputs and flags

1 inputs
NameTypeFlagDescription
sourceFOLDER--sourceFolder of Python source to scan.

Showing key inputs. bandit exposes 1 inputs in total.

example

Run bandit

bandit · command
bandit --source ./src
sample output
{"test_id": "B602", "issue_severity": "LOW", "filename": "app.py", "issue_text": "subprocess call with shell=True seems safe, but may be changed in the future, consider rewriting without shell"}

guidance

Choosing bandit

Use Bandit when the artifact is Python source. Use Semgrep for multi-language rules, and OSV-Scanner when the question is a lockfile advisory.

semgrep-scan

Runs custom rules across more languages than Python.

osv-scanner

Matches lockfiles to known vulnerability advisories.

gosec

Looks for security problems in Go source.

faq

bandit questions

Python files inside the connected folder. The smoke fixture was app.py.

Run bandit yourself

A folder containing app.py with subprocess.call and shell=True produced a JSON report that included B602.

Facts on this page come from the live Trickest tool library.