BarbacaneBLOCK
Barbacane API and Bidirectional AI Gateway
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Barbacane
Your spec is your gateway.
Barbacane is a spec-driven API gateway built in Rust. Point it at an OpenAPI or AsyncAPI spec and it enforces it: routing, request and response validation, authentication, rate limiting, a native WAF, and observability, all declared in the spec you already write. No proprietary config language, no drift between your spec and your infrastructure. The same middleware chain also routes LLM traffic and exposes your operations to agents as typed MCP tools.
- Spec as config — Your OpenAPI 3.x or AsyncAPI 3.x specification is the single source of truth. The compiler turns it into a sealed
.bcaartifact; no separate gateway DSL to maintain. - **A full API
cfa79733407eOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ui -- npx -y [email protected]
{
"mcpServers": {
"ui": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (9)
9 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
barbacane-auth-opt-out | read | Checks that operations explicitly opt out of global auth middleware |
barbacane-mcp-requires-fields | read | Validates that MCP-enabled operations have operationId and summary/description |
barbacane-no-plaintext-upstream | read | Warns when upstream dispatchers use plaintext protocols instead of HTTPS/WSS |
barbacane-no-unknown-extensions | read | Detects unknown x-barbacane-* extension keys |
barbacane-valid-path-params | read | Validates path parameters, supporting Barbacane |
barbacane-valid-secret-refs | read | Validates env:// and file:// secret reference format |
barbacane-validate-ai-regex | read | Compile-checks regex patterns in ai-prompt-guard and ai-response-guard profiles |
barbacane-validate-dispatch-config | read | Validates x-barbacane-dispatch.config against the dispatcher plugin schema |
barbacane-validate-middleware-config | read | Validates middleware config against the plugin |
Trust audit
BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- declared (14 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
split_host_port("169.254.169.254:9092", 9092),("169.254.169.254".into(), 9092)|| v4.is_link_local() // 169.254.0.0/16, incl. 169.254.169.254 cloud metadata
resolve_permitted_addrs("169.254.169.254", 80, false).await,DATABASE_URL ?= postgres://barbacane:barbacane@localhost:5432/barbacane
//! DATABASE_URL=postgres://barbacane:barbacane@localhost:5432/barbacane \
- **Pattern blocking** — regex-based prompt injection detection (blocks known jailbreak patterns)
format!("http://127.0.0.1:{}", self.admin_port)port_from_log_line("[stderr] barbacane: listening on http://127.0.0.1:52133"),port_from_log_line("[stderr] barbacane: admin API on http://127.0.0.1:41999"),port_from_log_line("[stderr] barbacane dev: listening on http://127.0.0.1:8080"),port_from_log_line("[stderr] barbacane: listening on https://127.0.0.1:8443"),DATABASE_URL: postgres://barbacane:barbacane@localhost:5432/barbacane
DATABASE_URL: postgres://barbacane:barbacane@localhost:5432/barbacane
DATABASE_URL: postgres://barbacane:barbacane@localhost:5432/barbacane
api_key: "sk-plaintext-should-warn"
.coderabbit.yaml
"SecRule ARGS \"@pmFromFile ../../etc/passwd\" \"id:2003,phase:2,deny\"\n",
assert_eq!(safe_filename("../../etc/passwd"), "passwd");const OPENAPI_SPEC: &str = include_str!("../../openapi.yaml");fixtures().join("../../plugins/mock/mock.wasm").display()"../../target/debug/barbacane",
"host must refuse outbound HTTP to 169.254.169.254 (metadata SSRF); \
@tanstack/react-query, ajv, ajv-formats, class-variance-authority, clsx, lucide-react, react, react-dom
| `env://` | `env://API_KEY` | Read from environment variable |
Gates applied: instruction_override, no_behavioural_pass.
cfa79733407efull audit observations/trust-audit/mcp-server/barbacane-dev__barbacane.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | cfa79733407e | BLOCK | F | 46 | first audit |
Questions
What is the Barbacane MCP server?
Barbacane API and Bidirectional AI Gateway
What tools does Barbacane expose?
9 in total: 9 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Barbacane safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (46/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Barbacane need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (cfa79733407e), read on 2026-10-08. The repository is watched and re-audited when it changes.