SECENG DEFEND
AI Runtime Configuration Security
Catch AI-specific misconfigurations before they reach production.
Scan .env files, Docker Compose, Kubernetes manifests, GitHub Actions, Vercel, Supabase, and other config formats for AI-specific unsafe defaults. Detect exposed model APIs, unauthenticated AI runtimes, permissive CORS, debug flags, missing auth, and provider credential risks before they become incidents.
Multi-format
Scan .env, Docker Compose, Kubernetes, GitHub Actions, Vercel, Supabase, and YAML/JSON configs in a single pass.
AI-specific rules
Rules tuned for AI-adjacent risks: exposed model endpoints, unauthenticated AI runtimes, vector DB exposure, and provider credential leaks.
Prioritized findings
Findings ranked by severity with specific line numbers, categories, and remediation guidance.
No execution
Static analysis only — no deployment access required, no production system interaction.
Core capabilities
What SecEng AI Config Linter does.
Environment Variable Analysis
Detect secrets in configs, public AI runtime binding, permissive CORS, debug flags, and missing auth across .env and example files.
Container & Compose Review
Flag AI service ports bound to 0.0.0.0, missing auth, no TLS termination, and unsafe default credentials in Docker Compose and Kubernetes.
CI/CD Pipeline Audit
Review GitHub Actions workflows for exposed AI provider keys, unsafe model endpoint usage, and missing secret controls.
Platform Config Review
Check Vercel, Supabase, and platform-specific configs for public AI endpoint exposure and missing access controls.
Prioritized Output
Every finding includes file path, line number, category, severity, evidence, and a specific remediation recommendation.
Evidence-Ready Export
Export findings as JSON for engineering backlog, Jira tickets, or security review evidence.
Evidence & signals
What you get out of the box.
Supported Formats
- .env / .env.example
- Docker Compose
- Kubernetes YAML
- GitHub Actions
- Vercel config
- Supabase config
- Generic JSON/YAML
Risk Categories
- Exposed model APIs
- Unauthenticated AI runtimes
- Permissive CORS
- Debug flags enabled
- Provider credential leaks
- Missing auth
- Vector DB exposure
Deliverables
- Prioritized findings
- Line-level evidence
- Remediation guidance
- JSON export
- Engineering backlog items
AI SECURITY ENGINEERING WORKBENCH
Ready to put SecEng AI Config Linter to work?
AI Config Linter is an active-development SecEng Workbench capability. We review your deployment configuration files and return prioritized findings without executing production workloads.
Also in the Workbench
WHAT AI DO WE HAVE?
SecEng Surface Scanner
Browser, Repo & IDE AI Discovery
WHERE CAN AI CODE BECOME AN ATTACK PATH?
SecEng Code Scanner
AI Attack-Path SAST
WHAT DID IT ACTUALLY DO?
SecEng Runtime Proxy
MITM Capture, Replay & Runtime Evidence
HOW CAN IT FAIL UNDER ATTACK?
SecEng Adversarial Range
AI Red-Team Scenario Harness
WHAT CAN AGENTS ACTUALLY DO?
SecEng Authority Graph
Agent Authority & Approval-Path Analysis
WAS RETRIEVAL AUTHORIZED?
SecEng RAG Test Harness
Retrieval & Context Security Test Harness
SecEng Threat Canvas
AI Threat Modeling & Trust-Boundary Mapping
SecEng Trust Scanner
Public AI Trust Signal Scoring
Atlassian Threat Canvas
Security Data Flow Canvas for Jira + Confluence
SecEng Agent Permission Analyzer
Agent Tool Permission Security Analysis
SecEng Artifact Analyzer
Static Artifact Intelligence
SecEng Injection Harness
Prompt Injection Testing
SecEng Prompt Reviewer
Prompt & Corpus Security Review
SecEng Model Gateway
Governed AI Routing, Policy Enforcement & Spend Control
SecEng Program Blueprint Kit
AI Security Program Build
SecEng Output Safety Tester
AI Output Safety Testing
SecEng Evidence Scorecard
AI Product Security Assessment & Maturity Scoring
WHAT CAN YOUR AI TOOLS REALLY DO?
SecEng Tool Capsule Analyzer
AI Tool Capability & Permission Analysis
WHERE ARE YOUR PRODUCTION PROMPTS?
SecEng Prompt Asset Scanner
Prompt Asset Inventory & Security Review
WHAT CAN YOUR AGENTS ACTUALLY DO?
SecEng Agent Authority Diff
Agent Authority Review & Hardening
WHICH AI DEPENDENCIES CHANGE RELEASE RISK?
SecEng Supply Chain Scanner
AI Supply Chain Risk Analysis
CAN YOU PROVE WHAT YOUR EVALS COVER?
SecEng Eval Coverage Auditor
AI Security Eval Coverage Evidence
AIPSA Evidence Packs
Structured Security Assessment Outputs