LLM Scanner
Close the AI supply chain blind spot. Checkmarx’s LLM Scanner exposes hidden code and security risks
inside your AI model packages before they ever run in production.
See the Hidden Code inside AI Model Packages
AI engineers pull models faster than security teams can review them. LLM Scanner closes that gap, scanning bundled source and binaries into actionable findings and a deterministic AI-BOM.
Scan Model Packages
LLM Scanner connects to Hugging Face repos, Git repos, local directories, and internal registries, extracting and cataloguing every source code file and binary artifact bundled inside AI model packages, so nothing enters your environment without review, including the pickle opcode gadget chains that no SAST or SCA tool was ever built to find.
Detect Unsafe Model Code Before It Runs
Surface insecure deserialization, trust_remote_code, command execution, dynamic eval, and other risks before models load in any environment. The model is never executed during the scan, so there is no risk of triggering the code you are trying to inspect.
Generate AI-BOM Evidence
View findings in Checkmarx One and generate deterministic AI-BOM output that records model provenance, findings, and risk posture for governance, audit, and AI adoption decisions.
Built-in to Checkmarx One
LLM findings surface in the same console, workflows, and ticketing integrations your team already uses, with broader coverage across SAST, SCA, DAST, and now, LLM risk.
AI Model Security Scanning
for Hidden Code Risks
AI models are more than weights and data. They often ship with bundled Python source and serialized artifacts that execute at load time, outside normal AppSec review and invisible to standard scanners.
AI models ship with source code
Your AppSec team never sees
Make hidden model code visible
LLM Scanner extracts and scans bundled source from every model package before runtime, so AppSec teams can see, triage, and stop risks that never reached SAST review.
Model artifacts are a blind spot your scanners can’t see
Coverage your existing tools can't reach
ML-aware analysis scans Python, notebooks, and binary model files, catching unsafe deserialization, command execution, and pickle gadget chains that SAST and SCA miss.
Regulators are asking for AI model evidence you can’t produce.
Regulators are asking for AI model evidence you can't produce.
Deterministic AI-BOM output documents model provenance, findings, and risk posture, giving teams audit-ready evidence for NIST AI RMF, EU AI Act, and ISO 42001 obligations.
Shadow AI in the SDLC: A Practitioner Panel on Visibility, Risk, and the Road to Governed AI
See how Checkmarx can help you regain visibility before AI governance gaps become an operational risk
Why the World’s Top Teams Choose Checkmarx
“We’ve seen an 80% noise reduction — our engineers now focus on the high-quality risks that matter.”Explore Best Buy Case Study
“By far the best AppSec tooling decision we have made”
“Checkmarx gave us a 90% reduction in vulnerabilities in just a few months.”
“Unifying our AppSec tools with Checkmarx gave us a single source of truth.”
“With 2.1B lines of code scanned monthly, Checkmarx gives us the scale and speed we need.”
“Checkmarx fits seamlessly into our DevOps pipelines—it’s a truly scalable solution.”
“From a buyer perspective, Checkmarx’s approach offers a structured and role-aware entry point into agentic security. ”
“Incorporating Checkmarx’s technology has revolutionized our development culture ”
“Checkmarx One made our security team and developers life easier.”
“The success of our AppSec program can be directly attributed to the tooling, processes and support provided by the Checkmarx managed services.”
“Bringing ASPM context directly into the IDE reflects a forward-looking approach to prioritizing security efforts based on risk earlier in the development process.”
Related Resources
The Model That Wrote Your Code Can’t Secure It
Go deeper on AI model risk, governance, and the controls security teams need as AI adoption moves from experimentation into production.
Read NowFrequently Asked Questions
Secure AI Model Packages Before Runtime
See how LLM Scanner uncovers unsafe code inside AI model packages before it reaches production, catching critical AI risks early and generating AI-BOM evidence in Checkmarx One.
Thank You!
Your Custom Demo Request is successfully sent. A member of Checkmarx Team would contact you shortly to set up your custom demo.
Personalized LLM Scanner Demo
Find Hidden Risk Inside Your AI Models
Scan Hidden AI Model Code
Inspect bundled Python files and model artifacts before any model runs in production.
Fit Your ML pipelines
Add CI/CD-native scanning with SARIF, JSON, YAML, or text output.
Binary-Level Coverage
Detect pickle opcode gadget chains and Torch rebuild helpers no SAST or SCA tool can reach.
Built-In AI Governance
Add scan findings to a deterministic AI-BOM to support NIST AI RMF, EU AI Act, and ISO 42001 requirements.
One Platform
Findings appear in Checkmarx One alongside SAST, SCA, and DAST, for unified risk intelligence
Catch High-Risk Patterns Early
Surface unsafe deserialization, command execution, and trust_remote_code risks early.
Scan Model Packages
Before They Run
AI models ship with hidden code most AppSec tools have never reviewed. LLM Scanner brings that blind spot into full view.