SECENG DEFEND
AI Supply Chain Risk Analysis
Find AI supply chain risk before it ships.
Scan AI SDKs, agent frameworks, model loaders, RAG libraries, vector database clients, notebooks, and workflow packages for supply-chain, version, and unsafe-loading risk. SecEng Supply Chain Risk augments SCA with AI-specific context; it does not replace OSV, GitHub Advisory DB, npm audit, pip-audit, Snyk, or existing dependency scanning.
Inventory
Identify AI-relevant packages across npm, Python, Docker, notebooks, and lockfiles.
Interpret
Explain why each AI dependency matters from a security perspective.
Prioritize
Surface unsafe loaders, agent frameworks, workflow tools, version drift, and release risks.
Complement SCA
Consume or complement advisory feeds without claiming to replace dependency scanners.
Core capabilities
What SecEng Supply Chain Scanner does.
AI Package Inventory
Identify AI SDKs, agent frameworks, model loaders, RAG libraries, vector database clients, notebooks, workflow packages, and eval tooling.
Model Loader Risk
Flag risky model loaders, serialization packages, unsafe artifact loading, and packages that should hand off to Artifact Analyzer.
Version Hygiene
Highlight unpinned versions, floating ranges, lockfile gaps, and version drift that can change model or framework behavior.
Advisory Context
Accept advisory feed inputs from OSV, GitHub Advisory DB, npm audit, pip-audit, or existing scanners and add AI-specific interpretation.
Release Readiness
Produce dependency risk findings, lockfile recommendations, and release-readiness signals for engineering review.
SCA Augmentation
Add AI-aware dependency interpretation while keeping existing SCA tools as the vulnerability matching source of record.
Evidence & signals
What you get out of the box.
Dependency Classes
- AI SDKs
- Agent frameworks
- Model loaders
- RAG libraries
- Vector stores
- Notebooks
- Workflow packages
Risk Signals
- Unsafe loaders
- Serialization risk
- Unpinned versions
- Version drift
- Weak lockfiles
- Advisory candidates
Deliverables
- AI dependency inventory
- AI package risk findings
- Version hygiene findings
- Advisory context
- Release readiness signals
AI SECURITY ENGINEERING WORKBENCH
Ready to put SecEng Supply Chain Scanner to work?
AI Dependency Risk is an active-development SecEng Workbench capability available through scoped public-site review conversations. It augments your dependency scanning with AI-specific interpretation, package context, and release-readiness signals.
Also in the Workbench
WHAT AI DO WE HAVE?
SecEng Surface Scanner
Browser, Repo & IDE AI Discovery
WHERE CAN AI CODE BECOME AN ATTACK PATH?
SecEng Code Scanner
AI Attack-Path SAST
WHAT DID IT ACTUALLY DO?
SecEng Runtime Proxy
MITM Capture, Replay & Runtime Evidence
HOW CAN IT FAIL UNDER ATTACK?
SecEng Adversarial Range
AI Red-Team Scenario Harness
WHAT CAN AGENTS ACTUALLY DO?
SecEng Authority Graph
Agent Authority & Approval-Path Analysis
WAS RETRIEVAL AUTHORIZED?
SecEng RAG Test Harness
Retrieval & Context Security Test Harness
SecEng Threat Canvas
AI Threat Modeling & Trust-Boundary Mapping
SecEng Trust Scanner
Public AI Trust Signal Scoring
Atlassian Threat Canvas
Security Data Flow Canvas for Jira + Confluence
SecEng Agent Permission Analyzer
Agent Tool Permission Security Analysis
SecEng Artifact Analyzer
Static Artifact Intelligence
SecEng Injection Harness
Prompt Injection Testing
SecEng Prompt Reviewer
Prompt & Corpus Security Review
SecEng Model Gateway
Governed AI Routing, Policy Enforcement & Spend Control
SecEng Program Blueprint Kit
AI Security Program Build
SecEng Output Safety Tester
AI Output Safety Testing
SecEng Evidence Scorecard
AI Product Security Assessment & Maturity Scoring
WHAT CAN YOUR AI TOOLS REALLY DO?
SecEng Tool Capsule Analyzer
AI Tool Capability & Permission Analysis
WHERE ARE YOUR PRODUCTION PROMPTS?
SecEng Prompt Asset Scanner
Prompt Asset Inventory & Security Review
WHAT CAN YOUR AGENTS ACTUALLY DO?
SecEng Agent Authority Diff
Agent Authority Review & Hardening
CAN YOU PROVE WHAT YOUR EVALS COVER?
SecEng Eval Coverage Auditor
AI Security Eval Coverage Evidence
ARE YOUR AI CONFIGS SAFE TO DEPLOY?
SecEng AI Config Linter
AI Runtime Configuration Security
AIPSA Evidence Packs
Structured Security Assessment Outputs