01AI Agent & MCP Server Discovery: Auto-detects and scans 20+ MCP clients and 427+ MCP servers.
02Comprehensive Vulnerability Scanning: Detects CVEs using multiple sources (OSV, NVD, EPSS, CISA KEV, GHSA, NVIDIA CSAF) across Docker, Kubernetes, cloud, and AI model files.
035 GitHub stars
04Tool Poisoning & Privilege Detection: Identifies tool poisoning risks via description injection and capability analysis, and detects privileged containers or shell access.
05Blast Radius Mapping: Correlates CVEs to affected packages, servers, AI agents, exposed credentials, and potential tools an attacker could leverage.
06Compliance & Posture Management: Evaluates posture against 10 security frameworks (OWASP LLM, MITRE ATLAS, NIST AI RMF, CIS, SOC 2, ISO 27001, EU AI Act) and generates detailed scorecards.