{"repo":"apisec-inc/AI-Surface","free":true,"listed":false,"github":"https://github.com/apisec-inc/AI-Surface","clone":"git clone https://github.com/apisec-inc/AI-Surface.git","description":"Find and govern AI attack surfaces in application code at PR time. Free, OSS, runs offline.","language":"Python","stars":99,"topics":["ai-security","devops","devsecops","github-action","llm","mcp","pr-review","static-analysis","ai-agents","ai-bom"],"license":"MIT","category":"ai-agents","readme_excerpt":"ai-surface Find the AI attack surface your code is about to ship. Locally, offline, before the PR merges. ai-surface maps the AI attack surface in your codebase: LLM calls, agents, MCP servers, RAG/vector stores, model gateways, self-hosted runtimes, provider keys, and the HTTP APIs that expose them. Run it locally or in CI to see what AI surfaces a PR introduces, generate an AI-BOM, and gate new high-risk findings before merge. Most layers of a codebase already have a check that runs before merge: Trivy for container images, Gitleaks for committed secrets, an SCA for dependencies. The AI layer, the agents, MCP servers, RAG, and LLM calls, has not had one. ai-surface is that check. Every risky finding carries a verdict: confirmed risk (an unambiguous fact of the code as written, like a financial-action tool with no approval step) or likely risk (inferred, wants a human look). Every scan ends on a scorecard with a posture grade. CI setup is one command: ai-surface init . It runs as a local static analysis pass that executes no code, makes no network calls, sends no telemetry, and requires no credentials, so your source never leaves the host. Try it without installing: If ai-surface is useful to you, star the repo so more engineers find it. Findings map to the OWASP LLM Top 10 and the EU AI Act, NIST AI RMF, and ISO 42001, so the AI-BOM doubles as governance evidence (see Compliance). Runtime exploit validation is out of scope for this OSS scanner. The optional --ui map shows d","default_branch":null,"files":null,"tree":[],"storefront":"/r/apisec-inc","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/apisec-inc/AI-Surface/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}