Skip to main content

AITrace — Attack Path Analysis and Exploit Synthesis for AI Applications

Traces user-controlled data through AI framework call chains across files and generates working exploit payloads from confirmed attack paths. Static analysis — no running application needed.

Supports LangChain · LangGraph · AutoGen · CrewAI · Semantic Kernel · LlamaIndex · Haystack · RAG pipelines · MCP servers · OpenAI / Anthropic / Cohere / Vertex AI SDKs · ChromaDB · Pinecone · FAISS and more.


What it does

  • Traces attack paths — Follows user input, env vars, and external data through AI framework calls across modules (not single-file grep)
  • Confirms reachability — Cross-file call-graph analysis marks which paths actually reach LLM, agent, code-exec, or SQL sinks
  • Synthesizes exploits — With --exploit, emits codebase-specific PoC payloads aimed at confirmed sinks, plus static CONFIRMED / LIKELY / UNCERTAIN verdicts
  • Surfaces AI stack context — Inventories LLM SDKs, agents, RAG, vector stores, and MCP configs so the path has a clear target map
  • One HTML report — Walk findings and (optional) exploit payloads in the browser after each run

Optional: CycloneDX / SPDX AI BOM and Mermaid architecture diagram via -f.


Installation

Requirements: Python 3.9+ · No telemetry · Core analysis makes no external API calls

From source (recommended — latest code):

git clone https://github.com/alishasinghania/AITrace-cli
cd AITrace-cli
pip install -e .

From PyPI:

# Install uv (if not already installed)
curl -LsSf https://astral.sh/uv/install.sh | sh   # macOS / Linux
# or: pip install uv

uv tool install aitrace-cli
# or: pipx install aitrace-cli

Note: The PyPI release may lag behind the GitHub repo. Install from source to get the latest features.


Usage

# Scan a local repo — writes aitrace-report.html and opens it
aitrace scan ./my-app

# Scan a remote GitHub repo directly (shallow clone, no setup needed)
aitrace scan https://github.com/owner/repo
aitrace scan https://github.com/owner/repo --exploit

# Generate PoC payloads from confirmed paths (+ RAG poison docs when RAG detected)
aitrace scan ./my-app --exploit

# Headless / CI — no browser
aitrace scan ./my-app --no-open

# Write to a specific directory
aitrace scan ./my-app -o ./results

# Optional machine-readable outputs
aitrace scan ./my-app -f cyclonedx -f spdx -f mermaid

# Policy gate — exits code 1 on violation (use in CI)
aitrace scan ./my-app --policy policy.yaml --no-open

# Write findings JSON + architecture graph
aitrace scan ./my-app --verbose

Output files

By default, all files are written into the scanned repository root. Use -o / --out-dir to choose another directory.

File When
aitrace-report.html Always (primary deliverable)
aitrace-exploits.json --exploit
aitrace-rag-poison-payload.txt --exploit + RAG detected
aitrace-cyclonedx.json -f cyclonedx
aitrace-spdx.json -f spdx
aitrace-component-diagram.mmd -f mermaid
aitrace-risk-report.md -f risk-md
aitrace-findings.json · arch graph --verbose

How it works

                      +-------------------------+
                      |      Your Codebase      |
                      |  Python · manifests     |
                      |  MCP configs · models   |
                      +----------+--------------+
                                 |
                                 v
                      +----------+--------------+
                      |     AITrace Scanner     |
                      +----------+--------------+
                                 |
          +----------------------+----------------------+
          |                      |                      |
          v                      v                      v
  +---------------+    +------------------+    +----------------+
  |   Discovery   |    |  Path Analysis   |    |  MCP Inspector |
  |               |    |                  |    |                |
  | · AI packages |    | · AST parser     |    | · tool desc    |
  | · agent shapes|    | · call graph     |    |   poisoning    |
  | · RAG / vector|    | · taint tracing  |    | · hardcoded    |
  | · model files |    | · pattern shapes |    |   credentials  |
  +---------------+    +------------------+    +----------------+
          \                     |                      /
           \                    v                     /
            +-------------------+--------------------+
            |            Analysis Engine             |
            |        PAT-001 … PAT-023 rules         |
            +-------------------+--------------------+
                                |
              +-----------------+-----------------+
              |                 |                 |
              v                 v                 v
     +----------------+  +-----------+  +----------------+
     |    Exploit     |  |   Risk    |  |    AI SBOM     |
     |  Synthesizer   |  |  Scoring  |  | CycloneDX/SPDX |
     |  (--exploit)   |  |  Policy   |  |   (-f flag)    |
     +----------------+  +-----------+  +----------------+
              \                |                 /
               \               v                /
                +-----------------------------+
                |      aitrace-report.html    |
                +-----------------------------+
  1. Discovery — Inventories AI packages, agent frameworks, vector stores, MCP servers, and model artifacts from manifests and imports.
  2. Path analysis — Builds a cross-file call graph, traces user-controlled data (routes, env vars, files) to LLM / exec / SQL sinks, and checks 23 structural vulnerability patterns.
  3. Exploit synthesis (--exploit) — Generates codebase-specific PoC payloads for confirmed paths with CONFIRMED / LIKELY / UNCERTAIN verdicts. Includes RAG poison documents for detected vector stores.
  4. Report — Single aitrace-report.html with grouped findings, MCP analysis, exploit gate, and architecture diagram.

Policy gate

Optional governance check for CI — not a substitute for path analysis:

aitrace init-policy
aitrace scan . --policy policy.yaml --no-open

Exit code 1 on violation. Example GitHub Actions step:

- name: AITrace policy gate
  run: aitrace scan . --policy policy.yaml --no-open

Metadata

Release files for aitrace-cli 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aitrace-cli 0.2.0
File Size Uploaded
aitrace_cli-0.2.0.tar.gz 199.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aitrace-cli 0.2.0
File Interpreter ABI Platform
aitrace_cli-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 413.4 kB

Release files / aitrace_cli-0.2.0.tar.gz

Download URL aitrace_cli-0.2.0.tar.gz
Size 199.7 kB
Tags Source
SHA-256 checksum
How to use checksums
9811cd9d84d951dbfc950236827333aff49dc7def4a6032ad687bedfa124c249
BLAKE2b-256 checksum
How to use checksums
2c9fa2f7829569326f453576b568b5d0d64b7f12db0299f82322905cfe14f7fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.29 {"installer":{"name":"uv","version":"0.11.29","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / aitrace_cli-0.2.0-py3-none-any.whl

Download URL aitrace_cli-0.2.0-py3-none-any.whl
Size 213.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0190fad9e15d5ce1214efc56ccefc58b04e344e8f23fd6515ec393e836bf3f3a
BLAKE2b-256 checksum
How to use checksums
16b26db4f3ef1c58150becb4cd496ac118db2c79c8574595da7f39928d3f7d50
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.29 {"installer":{"name":"uv","version":"0.11.29","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page