AI-Surface
View on GitHubFind and govern AI attack surfaces in application code, at PR time and inside your AI coding tool (MCP server, Claude Code hook). Free, OSS, runs offline.
A local, offline static-analysis tool that inventories AI components in application code and flags security risks across LLM calls, agents, MCP servers, RAG, and model gateways. Integrates with CI, Claude Code hooks, and MCP clients.
Use Cases
Scan application code for AI attack surfacesAudit MCP servers and permissionsGate new AI security findings in pull requestsGenerate an AI bill of materialsReview AI-related code changes in Claude Code or an MCP clientMap LLM, agent, RAG, and model-gateway integrations
Built With
- Language
- Python
- Frameworks
- LangChain · AWS Strands · MCP
Tags
AI security · static analysis · attack surface · AI-BOM · LLM security · MCP audit · CI/CD · offline · governance · Claude Code