PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

Deliverablesdeliverable
deliverable

Code Scanner Figures

Canonical figures for the Code Scanner.

Public sample
Client deliverable
public-sample
System
Code Scanner Figures
Environment
Production pilot

# Code Scanner Figures

SCN-01

AI-Native Scanner Coverage

The scanner evaluates AI-specific code and workflow surfaces that conventional AppSec categories do not fully describe.

Matrix showing scanner coverage across prompts, retrieval, agents, tools, MCP, authority, evidence, and lifecycle stages.

DiscoveryAnalysisEvidenceRetest
Prompts and instructionsSystem prompts, templates, policy text, and instruction boundaries.
Covered
Covered
Covered
Covered
Retrieval and contextCorpus access, provenance, tenant boundaries, and prompt assembly.
Covered
Covered
Covered
Partial
Agents and orchestrationPlanning, delegation, memory, and workflow transitions.
Covered
Partial
Partial
Planned
Tools and MCPTool schemas, invocation boundaries, and consequence-bearing actions.
Covered
Covered
Covered
Partial
Identity and authorityUser, agent, service, and delegated permissions.
Covered
Partial
Partial
Planned
Evidence and lifecycleFinding state, provenance, remediation, and rescan behavior.
Not applicable
Covered
Covered
Covered
CoveredPartialPlannedNot applicable
SCN-02

Scanner Workflow

The scanner moves from target discovery through analysis, evidence grouping, remediation, and rescan.

Six-stage scanner workflow from target discovery and normalization through analysis, evidence grouping, remediation handoff, and rescan.

Discover the targetSTEP 1Normalize contextSTEP 2Run AI-native analysisSTEP 3Group findings andevidenceSTEP 4Create remediationhandoffSTEP 5Rescan and updatestateSTEP 6Workflow controlsUnsupported targets remain explicit • Evidence state travels withthe finding • Rescan updates rather than erases history
SCN-03

Scanner Output Contract

One scan can produce machine-readable findings, reviewable evidence, path inputs, and remediation-ready artifacts.

Layered scanner output stack from raw analysis evidence through structured findings, path inputs, remediation records, and reports.

PROVENANCEAnalysis evidenceSource location and rule evidenceTrace or data-flow contextConfiguration and permission contextStructured findingsFindings JSONSARIFReviewable MarkdownPath and graph inputsEntity and relationship referencesEvidence-linked transitionsValidation and lifecycle stateRemediation and retestOwner and remediation recordRescan and retest resultRegression fixture when supportedCONSUMERSCI and developerworkflowAppSec reviewGraph and Attack PathAnalysis analysis
SCN-04

AI Scanner and Conventional AppSec

AI-native analysis extends conventional code scanning by following prompts, retrieval, tools, agents, and authority through application logic.

Comparison of conventional application security analysis and AI-native analysis across code, prompt, retrieval, agent, tool, and authority relationships.

BEFOREConventional AppSec coverageCode and dependency weaknessesConfiguration and secret exposureApplication data flowWeb and API behaviorAFTERAI-native extensionPrompt and instruction boundariesRetrieval and provenanceAgent and workflow compositionTool and MCP invocationDelegated identity and authorityQUALIFIED INTORESPONSIBLE COMPARISONExtends rather than replaces AppSecClaims remain capability-specificNo claim that every conventional scannerlacks AI coverage