AI SUPPLY-CHAIN ANALYSIS

Inspect a repository

Discover AI components, prioritize supply-chain risks, and trace every finding to file-and-line evidence.

01

Repository scan

  1. 1 Enter repository URLGitHub, GitLab, Bitbucket, or Codeberg
  2. 2 Run the scanFiles and advisories are inspected
  3. 3 Review the evidenceFindings, graph, inventory, and exports
What it scans: a two-file FastAPI + OpenAI Agents app shipped inside AIBOM Inspector as a test fixture — deliberately vulnerable, and never executed. An HTTP request body is concatenated into the agent's instructions, and that agent is bound to a tool that runs shell commands. No repository URL, API key, or internet access needed.

Static analysis only: files and manifests are read as text. Repository code is never run and model weights are never loaded. Package advisories come from OSV; every finding comes from a deterministic rule, not a model.

02

Analysis results

Waiting for input
READY

No analysis loaded

Enter a repository URL above and start the analysis. Findings and evidence will appear here.

Help and input formatsQuick guidance for running an analysis

Getting started

  1. Paste a complete public repository URL.
  2. Select Start analysis and keep the page open.
  3. Review critical and high findings before lower severities.
  4. Export the HTML report or CycloneDX file when needed.

Accepted inputs

  • GitHub: https://github.com/owner/repository
  • GitLab: https://gitlab.com/owner/repository
  • Bitbucket: https://bitbucket.org/owner/repository
  • Codeberg: https://codeberg.org/owner/repository