AGENT SUPPLY-CHAIN SECURITY

AgentST

Agent Supply‑Chain Security

Assess agents, models and dependencies for vulnerabilities, malicious files, unsafe content and license risks

AGENT INTELLIGENCEIllustrative workflow
Illustrative agent security assessment, not a live scan. All objects and test content are fictional. Load a document assistant and its runtime, then map its model, Skills, Plugins, MCP and API dependencies. A prompt injection test introduces external content that tries to redirect a summarization task. The observed DONE response is recorded as an instruction deviation risk for review. Model AI-BOM, extension checks and behavior test records support pre-deployment review. Dependency lines do not indicate attack propagation. AI-BOM is scoped to the model. This does not imply automatic blocking, a confirmed vulnerability or deployment approval.
Open-source Skills
50K+
Open-source models
3M+
Core security detection rules
100+
Skills and Plugins risk categories
9
Supported model file formats
10+
Large-model support
50GB+

PRODUCT OVERVIEW

Assess risk acrossthe agent supply chain

Assess vulnerabilities, malicious files, content safety and license compliance across agents, foundation models and runtime dependencies

Combine agent behavior tests, foundation-model verification, model-file inspection and interface testing. Map model composition with an AI-BOM to guide remediation before deployment

CORE CAPABILITIES

Core capabilities

04 GROUPS / 08 CAPABILITIES

Multi-turn conversation testing

Test multi-turn conversations for logic manipulation, memory poisoning and decision hijacking

Prompt injection testing

Detect prompt injection and manipulation that attempt to bypass system instructions

Script and command testing

Inspect scripts and command execution for security risks, including unauthorized commands that could compromise servers

Skills & Plugins inspection

Inspect Skills and Plugins for malicious content and vulnerabilities before installation and use

01 / AGENT SECURITY
Four assessment surfaces across agent behavior and extensions
AI AGENTAgent & runtime dependencies
01 / CONVERSATIONMulti-turn conversation

Logic manipulation, memory poisoning and decision hijacking

02 / INSTRUCTIONSPrompt injection

System-instruction bypass and prompt manipulation

03 / EXECUTIONScripts & commands

Unauthorized command execution

04 / EXTENSIONSSkills & Plugins

Malicious content and vulnerabilities in extensions

AGENT ASSESSMENTIdentify potential risks before installation, use and deployment
Conceptual illustration · Not actual analysis results

USE CASES

Use cases

01 — 03

LLM compliance before filing

Self-assess model outputs against GB/T 45654-2025 and address compliance risks to improve the chance of passing the first filing review

Foundation-model provenance

Trace open-source foundation-model origins, versions and derivatives. Build an AI-BOM to understand supply-chain composition and provenance and strengthen governance

Pre-deployment agent assessment

Assess external-facing agents for non-compliant content and malicious exploitation risks before production deployment to support remediation and release review

See AgentST in action

See how to check AI agents, models and their dependencies for security and compliance risks before deployment.

Request a Demo