Ross ROSS = Recommend OSS · open-source software intelligence for agents

blst-security/cherrybomb

Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests. observed · 2026-08-28

github.com/blst-security/cherrybomb · Rust · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1750
  • days_rel: n/a
  • days_push: 677
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1234 stars · 84 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Cherrybomb is a Rust-based CLI tool that audits OpenAPI specifications for best practices and OAS compliance, then runs security tests against the API to find undefined user behavior and vulnerabilities. It produces detailed reports pinpointing the exact location of issues.

Use cases

  • validate my OpenAPI spec against OAS rules
  • audit my API specification for security issues
  • find undefined user behavior in my API
  • run automated security tests on my REST API
  • check my API spec for best practices before release
  • scan an OpenAPI file for vulnerabilities

When to choose

  • you have an OpenAPI/Swagger spec and want early detection of security and correctness issues
  • you want a lightweight CLI that fits into CI pipelines for API spec auditing
  • you need detailed reports showing exactly where spec problems are

When to avoid

  • your API has no OpenAPI specification
  • you need runtime DAST scanning of a fully deployed production API rather than spec-based auditing
  • you require a GUI or hosted SaaS scanning platform

Facets

cli-tool · maturity maintenance

security vulnerability-scanning cli testing security apis developer-tools web-development cli windows rust openapi api-security spec-validation business-logic web-security-scanner linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
blst-security/cherrybombmain23

For agents

markdown · JSON · MCP: product_card(name="blst-security/cherrybomb")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem