Check a project's AI dependencies before you ship: the LLM SDKs, agent frameworks and MCP components it pulls in, known vulnerabilities in the exact versions it pins, the host authority its dependencies grant to a model, and the controls that follow from those facts.
Supports npm, PyPI, Go and crates.io manifests and lockfiles, and CycloneDX or SPDX SBOMs. Results download as JSON or as a CycloneDX AI-BOM. Vulnerability data comes from OSV; LLM components and indirect exposure come from the Exposure Registry.
Up to 5 files: manifests and lockfiles up to 2 MB, CycloneDX or SPDX SBOMs up to 5 MB. Lockfiles and SBOMs give version-exact results.
Files are processed in memory and not stored. Nothing is kept after the response.
The same check is an API call. Send up to five files; add ?format=markdown for a report you can paste into a pull request, or ?format=cyclonedx for an AI-BOM.
curl -s https://aisecwatch.com/api/v1/check?format=markdown \
-H "Content-Type: application/json" \
-d "$(jq -n --rawfile c package-lock.json '{files:[{filename:"package-lock.json",content:$c}]}')"Coding agents can call it through the MCP server with the check_stack tool. Field reference in the API documentation.