This tool automates comprehensive open-source supply chain risk analysis by empowering AI agents with direct access to seven live intelligence sources. It queries GitHub, NVD, CISA KEV, Hacker News, StackExchange, ArXiv, and Censys concurrently to deliver SBOM-grade risk intelligence. Designed for security engineers and DevSecOps teams, it significantly reduces the time and cost associated with manual audits, providing always-current data and actionable insights to quickly assess package vulnerabilities, maintainer health, and potential threats within an AI-assisted workflow.
주요 기능
01SBOM-aware report generation
02CVE blast radius estimation
035-factor weighted supply chain risk scoring
040 GitHub stars
05Maintainer bus-factor scoring
06Typed OSS dependency network graph