SECENG WORKBENCH
Browser, Repo, IDE & Surface Discovery
Find AI systems, data paths, and tool boundaries before they become attack surfaces.
SecEng Surface Scanner inventories AI apps, model calls, prompts, RAG paths, agents, MCP servers, browser extensions, IDE plugins, and external tool boundaries so teams know what exists before they assess, harden, or evidence it.
Vendor Registry
Resolve model providers, SDKs, agent frameworks, widgets, and runtimes from one canonical catalog.
Browser Snapshot Input
Accept live browser snapshots with HTML, DOM, globals, storage, network, and header signals.
Signal Breadth
Trace DOM markers, script URLs, runtime globals, cookies, URL hints, and API endpoints.
Public-Safe Output
Export confidence, family summary, evidence hits, and catalog version for downstream automation.
1,000+
AI technologies across vendors, SDKs, tools, and runtimes in the embedded catalog
10
signal families evaluated per browser snapshot
23
detection families spanning model providers to commerce AI
1
shared source of truth across WASM, routes, and UI
Core capabilities
What SecEng Surface Scanner does.
AI Vendor & Runtime Detection
Detect model providers, inference runtimes, coding assistants, voice AI, document extraction, commerce AI, generative media, and enterprise copilots from the same catalog — over 1,000 entries across 23 detection families.
SDK, Widget, and Framework Classification
Classify LangChain, LangGraph, LlamaIndex, Semantic Kernel, AutoGen, CrewAI, Haystack, Dify, Flowise, Botpress, Voiceflow, Intercom Fin, Botsonic, Ada, Crisp, Zendesk AI, Gorgias, and hundreds of similar embedded surfaces.
Browser Runtime Fingerprinting
Use HTML, DOM, globals, cookies, storage, URL, network, and script-path heuristics to find AI surfaces that do not self-report cleanly.
Snapshot-Native Analysis
Accept live browser snapshots from crawlers or extension-based capture and return ai_matches, ai_family_summary, snapshot_summary, and catalog_version in one payload.
Public-Safe Inventory Export
Export a structured inventory with confidence, family labels, evidence hits, public_safe flags, and canonical vendor metadata for downstream reporting.
Live Scan Harness
Use the browser harness and snapshot route to iterate against real pages, DOM captures, and local fixtures without forking the detection logic.
Evidence & signals
What you get out of the box.
Detected Families
- Model Providers
- SDKs & Frameworks
- Inference Runtimes
- Vector Databases
- Guardrails & Evals
- Developer Tools & Coding AI
- Voice & Meeting AI
- Document & OCR AI
- Commerce & Personalization AI
- Generative Media & Avatars
- Analytics & Experimentation AI
- Support & Enterprise Copilots
Signal Sources
- HTML
- Scripts
- DOM
- Globals
- Headers
- Cookies
- Storage
- URLs
- Network
Output Fields
- ai_matches
- ai_family_summary
- catalog_version
- snapshot_summary
- public_safe
- confidence
Red team + Blue team
Built for both sides of the security equation.
Red Team Use
- Find hidden attack surface: undocumented AI endpoints, embedded widgets, runtime globals, and SDK bundles
- Identify shadow AI providers and tool calls before they spread across the product estate
- Trace browser-level signals that a vendor never documented but still ships in production
Blue Team Use
- Produce an AI asset register with vendor, family, confidence, public-safe flag, and evidence hits
- Generate evidence bundles for product security, governance, and executive reporting
- Keep the WASM, route, and browser harness aligned to one shared catalog and schema
How teams use it
Surface inventory turns into RAG boundary plans, threat models, and governance evidence.
Shared component
Trace, Chrome, and Surface now use the same RAG lens
The demo keeps the public story honest: the Surface page shows the discovery layer, and the RAG lens shows how those signals turn into boundary plans, testcases, and evidence classification.
Discovery
Surface map
Boundary
Scorecard flow
Output
Harness bundle
Public-safe fixture scope
The lens exposes the artifact names, control paths, and test intent without publishing raw documents, raw answers, or private payloads.
SecEng RAG Test Harness
RAG Boundary Lens
Boundary planning, testcase generation, and evidence classification rendered from the same public-safe trace fixture.
AuthZ pass
Retrieval gates are mostly aligned.
Context leaks
No leak-shaped signals surfaced.
Policy violations
Policy language needs stronger enforcement.
Pipeline snapshot
5Suggested tests
3Controls found
3Affected paths
2Missing boundaries
Priority gaps
Top tests
Harness checks
The lens is public-safe and directional. It uses job-description intelligence and trace fixture signals to show where RAG boundaries need reinforcement, without exposing raw documents or private payloads.
Related Workbench tools
SECENG WORKBENCH
Map the AI surface before it becomes an attack surface.
Scope a Workbench-backed review to inventory AI apps, providers, SDKs, browser signals, RAG paths, agents, tools, and evidence gaps.