PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

AI SECURITY WORKBENCH · ARTIFACT ANALYSIS

Static Artifact Intelligence

Understand what an AI artifact appears capable of doing before it runs.

Artifact Analyzer turns approved static artifacts into analyst-ready facts, capability signals, authority indicators, provenance, confidence, caveats, and deeper-review targets. It provides structured triage without presenting static indicators as proof of runtime behavior.

WHAT'S INSIDE YOUR AI ARTIFACTS?

Artifact identity

Format, architecture, hashes, language, compiler or runtime indicators, packaging, provenance, and evidence quality.

Capability signals

Network, process, filesystem, credential, browser, MCP, agent, provider, retrieval, persistence, and external-action indicators.

Evidence and relationship exports

Structured facts, supported signals, confidence, caveats, graph-compatible relationships, and evidence references.

Analyst next steps

Prioritized reverse-engineering, sandbox, configuration, identity, permission, provenance, and runtime-review targets.

Important caveat

Artifact Analyzer is not a decompiler replacement and does not prove that a capability was exercised. It provides structured static triage showing what the artifact appears to contain, which behaviors may be possible, what evidence supports that view, and where analyst or runtime review is required.

What it analyzes

Built for modern AI and security artifacts.

Teams are shipping agents, MCP servers, local copilots, native browser helpers, CLIs, and infrastructure tools — often in Rust or Go, often with broad authority. Static-first triage gives analysts a starting point before deeper review.

Rust binaries

Detect crate markers, demangled symbols, panic/runtime evidence, async/runtime/webview/AI provider hints, crypto and system capability signals, and authority-related patterns.

Go binaries

Recover Go build info, module/package paths, function names, GoReSym/Redress signals, process/network/plugin/container/Kubernetes/MCP markers, and embedded retrieval or provider clues.

Agent and MCP artifacts

Find tools/list, tools/call, resources/list, prompts/list, JSON-RPC, stdio/SSE/HTTP, browser bridge markers, model provider signatures, retrieval or vector store authority, and tool execution intent.

Generic executables

Extract format, architecture, sections, imports, symbols, entropy, stripped/packed hints, language/runtime by inference, authority signals, and evidence quality caveats across ELF, PE, and Mach-O.

Analysis workflow

Fingerprint the artifact. Classify the capabilities. Preserve the evidence.

1

1. Identify the artifact

Format, architecture, hash, sections, imports, symbols, strings, compiler indicators, runtime clues, package hints, and embedded configuration.

2

2. Classify capability signals

Network, process, filesystem, credential, persistence, agent, MCP, browser, provider, retrieval, administrative, and external-action indicators.

3

3. Identify authority implications

Determine which identities, credentials, scopes, tools, APIs, or trust boundaries may require deeper review.

4

4. Produce analyst targets

Create focused reverse-engineering, sandbox, permission, runtime, and hardening questions.

5

5. Preserve the evidence

Return structured facts, signals, confidence, caveats, provenance, findings, and relationship exports.

Tool integration

Normalize evidence from specialist analysis tools.

The analyzer normalizes evidence from Goblin, Ghidra Headless, GoReSym, Redress, capa, rizin/rabin2, rust demangling, YARA, and Workbench scanners into one structured artifact-analysis model — so you get one structured output instead of six different formats to correlate manually.

What the report produces

Analyst-ready findings, packaged as evidence.

Artifact facts

Hashes, format, architecture, size, section summary, language or runtime guess, compiler evidence, and tool output provenance.

Capability signals

Network, process, filesystem, crypto, persistence, credential, agent, MCP, RAG, and supply-chain behavior signals.

Authority indicators

Identities, credentials, scopes, tools, APIs, or trust boundaries the artifact appears able to reach.

Embedded configuration and evidence

URLs, domains, IPs, file paths, environment variables, command strings, suspicious package or crate markers, embedded prompts, and redacted secrets.

Risk findings

Prioritized findings with severity, confidence, rationale, evidence references, caveats, and analyst next steps.

Analyst review targets

Prioritized reverse-engineering, sandbox, configuration, identity, permission, provenance, and runtime-review targets.

Graph-compatible relationships

Supported entity relationships exported in a form downstream analysis and Threat Canvas can consume.

Public-safe summary

A redacted summary suitable for buyer review, partner assessment, or executive reporting.

Evidence bundle

artifact.analysis.json, artifact.report.md, artifact.public-summary.md, artifact.iocs.json, artifact.yara, graph.json, and evidence bundle.

Product modes

Use it four ways.

Quick triage

Upload or import artifact facts and get a fast language, runtime, capability, and authority risk report.

Rust / Go deep profile

Run Rust and Go-specific recovery and generate analyst targets for runtime, compiler, and capability review.

Agent / MCP profile

Surface agent, MCP, browser, and provider authority markers so security teams can review exposed surfaces before release.

Evidence and relationship export

Export findings, indicators, supported entity relationships, Mermaid views, public-safe summaries, and evidence bundles for downstream analysis.

Honest limitations

What this does not claim.

It does not prove that an artifact is safe.

It does not prove that a detected capability executes at runtime.

It does not replace manual reverse engineering for high-risk cases.

It does not guarantee source recovery.

It does not execute suspicious binaries by default.

It does not publish proprietary strings, secrets, or customer evidence.

Packed, stripped, obfuscated, encrypted, or runtime-configured artifacts reduce confidence.

Dynamic behavior may require authorized sandbox execution or Runtime Trace analysis.

Delivery & licensing

Available through the model that fits the product outcome.

Expert-led engagement

AI Security LLC analyzes submitted binaries or artifacts directly as part of an assessment.

Bounded partner pilot

One representative binary or artifact class is analyzed and returned as a structured signal report.

OEM or licensed capability

The analyzer can run headless behind a partner's own build pipeline, MCP registry, or supply-chain review product.

Accepts

Rust and Go binaries, browser bundles, and MCP or agent artifacts.

Returns

Artifact identity, capability signals, authority indicators, confidence, caveats, relationship exports, evidence references, and analyst review targets.

Current maturity

Fixture-tested

Explore Offensive Security Platforms

AI SECURITY WORKBENCH

Turn unknown AI artifacts into bounded analyst questions and reviewable evidence.

Use Artifact Analyzer for third-party component review, agent or MCP triage, supply-chain investigation, launch review, and preparation for deeper reverse engineering or controlled runtime analysis.