About AI Sec Watch
An open vulnerability check for AI software: what a project's AI dependencies expose, at the versions it runs.
Why it exists
Software now hands authority to language models. A model reads text it did not write, such as a web page, a document or a tool result, and the code around it then runs commands, opens files, browses or calls other tools with the permissions of the application. Developers inherit this through dependencies they did not choose, and it rarely shows up in a dependency list or a scanner report.
AI Sec Watch exists to make that delegation visible, so the people who build, study and regulate AI software can see where the risk sits before it ships.
How it works
- Exact. Stack Check reports the advisories that affect the versions a project pins, from OSV, and the Exposure Registry reads each package's own registry metadata release by release.
- Traceable. Every record links to its public source. Methods, prompt versions and limits are published on the methods page, pipeline health on the status page, and every record has a correction form.
- Open. No login. A public API, tools for coding assistants over MCP, badges, feeds, and dataset releases under CC-BY-4.0 with a DOI.
- Current. 84 sources are fetched every six hours. Topics, the catalog of LLM SDKs and agent frameworks, and the source list are kept as data, so when the field produces a new protocol or attack class, it is added once and the archive is tagged again.
What you can use
- Stack Check
- Send a lockfile, manifest or SBOM; get vulnerabilities in the pinned versions with fixed versions, the LLM components in use, dependencies that reach one indirectly, the authority the dependencies grant, and controls.
- Exposure Registry
- Open-source packages that delegate to language models: when each first declared an LLM dependency, what host authority it carries, and which packages inherit it (3,999 packages tracked so far).
- Advisories and Topics
- Vulnerabilities, incidents, research and policy on AI security, 8,003 records so far, with severity, exploitation signals, fixes and trends by subject.
- Dataset
- Versioned releases for research, with a codebook and citation formats.
Who maintains it
AI Sec Watch is built and maintained by Truong (Jack) Luu, an information systems researcher who studies AI security and how software delegates authority to language models. The site has no sponsors and no paywall. Corrections, source suggestions and research collaborations are welcome through the contact details on that site.
To cite the platform or a dataset release, see citation formats.