ARC AI Security Scanner
Defensive security review for AI applications.
Describe an AI application — agents, MCP, RAG, prompts, data flows — and get a graded defensive review covering prompt injection surface, tool authority, data exposure, tenancy, and logging. Every finding quotes your own words. Not a penetration test and not a certification. The disclosures stacking up this year are not clever jailbreaks: they are ordinary links and documents that turn a connected assistant into an exfiltration path with the permissions you already granted it.
- Instruction boundaryCritical
- Tool permissionssend_email · run_sql
- Retrieval ACLNo per-user filter
- SecretsNEXT_PUBLIC_ key
- ScoreConfig review · not a pentest
What it does
- Free on the site — no account, no email gate
- 19 published SEC-* rules across boundary, tools, RAG, secrets, observability, egress
- Every finding cites a verbatim quote from your input
- Score from a published rubric, never from a model
- Markdown / JSON export and a CLI
How it works
- 1Paste a sanitized architecture description, prompt pattern, tool list, or RAG data-flow.
- 2Deterministic rules match that text. No model produces a finding or a score.
- 3You get a surface inventory, evidence-backed findings, remediation, and a sequenced defensive blueprint.
- 4Where the description is silent, the report says so. Nothing you paste is stored.
Who it’s for
Engineering, security, platform, and AI teams building RAG systems, agents, or MCP-based apps who need an explainable configuration review — not a green checkmark and not an exploit kit.
What’s next
- Rule pack + evidence-backed findings — shipped
- Surface inventory + golden suite — shipped
- Production deploy — shipped
- Optional model narrative (phrasing only)
Need a human to read this report?
The report is the start. Studio turns findings into a plan with owners. Thirty minutes to see if that's worth it.