Static Code Analysis
Find shell injection in a Python folder
Python source in, JSON security findings out.
overview
What bandit does
Bandit reads a connected folder of Python files, parses each file into an AST, and writes a JSON report of plugin hits.
A Managed-fleet smoke on a two-line script that calls subprocess with shell=True returned B602, the shell-injection check, in that JSON report.
Connect the folder that holds the .py files. A bare text file is not scanned as Python.
source github.com/PyCQA/bandit
use cases
Where bandit fits
Scan application source
Point Bandit at the folder that contains the Python modules you ship.
Catch shell invocation
Surface subprocess calls that pass shell=True before that code runs.
Hand JSON to triage
Keep the plugin id, filename, and issue text in one report for a later node.
reference
bandit inputs and flags
| Name | Type | Flag | Description |
|---|---|---|---|
| source | FOLDER | --source | Folder of Python source to scan. |
Showing key inputs. bandit exposes 1 inputs in total.
example
Run bandit
bandit --source ./src{"test_id": "B602", "issue_severity": "LOW", "filename": "app.py", "issue_text": "subprocess call with shell=True seems safe, but may be changed in the future, consider rewriting without shell"}guidance
Choosing bandit
Use Bandit when the artifact is Python source. Use Semgrep for multi-language rules, and OSV-Scanner when the question is a lockfile advisory.
semgrep-scan
Runs custom rules across more languages than Python.
osv-scanner
Matches lockfiles to known vulnerability advisories.
gosec
Looks for security problems in Go source.
faq
bandit questions
related
More Static Code Analysis tools
gitleaks
Detect hardcoded secrets in git repos and plain directories.
gosec
Go AST security scanner for credentials, crypto, and injection.
guarddog
A package coordinate in, indicator hits out.
malcontent-scan
A package coordinate in, behavior findings out.
osv-malicious
A package coordinate in, malware advisory rows out.
osv-scanner
A lockfile in, advisory rows out.
Run bandit yourself
A folder containing app.py with subprocess.call and shell=True produced a JSON report that included B602.
Facts on this page come from the live Trickest tool library.