No confabulated findings.
Every LLM-produced claim must carry a verbatim file:line quote. The validator physically re-reads the source and drops evidence that does not match.
Assay threat-models MCP servers, Claude Code plugins, hooks, skills, and connectors—then investigates the source and validates every citation against real code.
T4 · EXFILTRATIONThe server reads process credentials and constructs an outbound request in the same execution path.
headers.set("Authorization", token)Watch Assay discover the installed AI dev stack, generate a threat model, investigate the source, and produce a report you can audit.
Assay starts with intent and capability, not a bag of regexes. Explore the stages to see what each one contributes.
Claims, manifests, and exposed capabilities become a target-specific threat model across twelve AI-native risk classes.
Explore the methodologyEvery LLM-produced claim must carry a verbatim file:line quote. The validator physically re-reads the source and drops evidence that does not match.
Your source stays on your machine. The default path runs through your existing Claude Code subscription.
Prompt injection, tool poisoning, grant abuse, exfiltration, confused deputies, hooks, supply chain, and more.
Human-readable Markdown, versioned JSON, SARIF export, CI gates, and clear safe / caution / unsafe verdicts.
Build the self-contained binary, inventory your installed tools, and open the local web UI.
Read the full quickstart# build Assay
git clone https://github.com/chawdamrunal/assay.git
cd assay && make build && make install
# inspect, then launch
assay inventory
assay serve