---
title: "LLM Scanner"
date: "2026-07-10T15:47:20+00:00"
url: "https://checkmarx.com/platform/llm-scanner/"
description: "Scan hidden code inside AI model packages before runtime. Checkmarx detects unsafe deserialization, command execution, and artifact-level risk. Generate AI-BOM evidence inside Checkmarx One."
---

# LLM Scanner

 Checkmarx One – AI Supply Chain Security

# LLM Scanner

Close the AI supply chain blind spot. Checkmarx’s LLM Scanner exposes hidden code and security risks
 inside your AI model packages before they ever run in production.

 [Get a Demo](#form) [Discover More](#more)

AI Model Security Scanning

## See the Hidden Code inside AI Model Packages

AI engineers pull models faster than security teams can review them. LLM Scanner closes that gap, scanning bundled source and binaries into actionable findings and a deterministic AI-BOM.

  01  Scan Model Packages Uncover Hidden Model Code    02  Detect Unsafe Model Code Before It Runs Eliminate risk before runtime    03  Generate AI-BOM Evidence Governance Ready    04  Built-in to Checkmarx One Platform Native

ML-aware static analysis

### Scan Model Packages

LLM Scanner connects to Hugging Face repos, Git repos, local directories, and internal registries, extracting and cataloguing every source code file and binary artifact bundled inside AI model packages, so nothing enters your environment without review, including the pickle opcode gadget chains that no SAST or SCA tool was ever built to find.

 [ See it in Action  ](#form) ![Screenshot of a dark-themed software interface displaying AI asset scan results and a detailed view of a GPT-4o configuration with a highlighted code snippet.](https://checkmarx.com/wp-content/uploads/2026/07/llm_feature_scan_review_and_fix_2x.webp)

Pre-Runtime Findings

### Detect Unsafe Model Code Before It Runs

Surface insecure deserialization, trust\_remote\_code, command execution, dynamic eval, and other risks before models load in any environment. The model is never executed during the scan, so there is no risk of triggering the code you are trying to inspect.

 [ See It in Action  ](#form) ![A dark-themed UI showing 'Project Sol (Scan Results)' with a list of AI assets and their states, alongside an 'AI SUPPLY CHAIN' panel detailing 'GPT-4o' risks, including 'Unsafe Deserialization in Code' with code snippet.](https://checkmarx.com/wp-content/uploads/2026/07/llm_feature_detect_unsafe_model_code_before_it_runs_2x.webp)

Deterministic AI-BOM

### Generate AI-BOM Evidence

View findings in Checkmarx One and generate deterministic AI-BOM output that records model provenance, findings, and risk posture for governance, audit, and AI adoption decisions.

 [ See It in Action  ](#form) ![A dark-themed dashboard showing an 'AI Supply Chain Global Inventory' table with asset details and an 'Export AI-BOM report' modal window open, offering options for standard and format.](https://checkmarx.com/wp-content/uploads/2026/07/llm_feature_generate_ai_bom_evidence_2x.webp)

Platform Native

### Built-in to Checkmarx One

LLM findings surface in the same console, workflows, and ticketing integrations your team already uses, with broader coverage across SAST, SCA, DAST, and now, LLM risk.

 [ See It in Action  ](#form) ![llm_feature_built_in_to_checkmarx_one](https://checkmarx.com/wp-content/uploads/2026/07/llm_feature_built_in_to_checkmarx_one.webp)

AI Model Security

## AI Model Security Scanning for Hidden Code Risks

AI models are more than weights and data. They often ship with bundled Python source and serialized artifacts that execute at load time, outside normal AppSec review and invisible to standard scanners.

Problem

AI models ship with source code
Your AppSec team never sees

 ![Shield AI Security](https://checkmarx.com/wp-content/uploads/2026/06/Shield-AI-Security-1.svg)

Solution

### Make hidden model code visible

LLM Scanner extracts and scans bundled source from every model package before runtime, so AppSec teams can see, triage, and stop risks that never reached SAST review.

Problem

Model artifacts are a blind spot your scanners can’t see

 ![Warn](https://checkmarx.com/wp-content/uploads/2026/06/Warn-1.svg)

Solution

### Coverage your existing tools can't reach

ML-aware analysis scans Python, notebooks, and binary model files, catching unsafe deserialization, command execution, and pickle gadget chains that SAST and SCA miss.

Problem

Regulators are asking for AI model evidence you can’t produce.

 ![Compliance-Ready-V2](https://checkmarx.com/wp-content/uploads/2026/06/Compliance-Ready-V2.svg)

Solution

### Regulators are asking for AI model evidence you can't produce.

Deterministic AI-BOM output documents model provenance, findings, and risk posture, giving teams audit-ready evidence for NIST AI RMF, EU AI Act, and ISO 42001 obligations.

 [See it in Action](#form)

See it in Action

## Shadow AI in the SDLC: A Practitioner Panel on Visibility, Risk, and the Road to Governed AI

See how Checkmarx can help you regain visibility before AI governance gaps become an operational risk

 [Request a Demo](#form) [Watch Now](https://checkmarx.com/shadow-ai-in-the-sdlc/)

 ![Gartner Logo - CTA Awards](https://checkmarx.com/wp-content/uploads/2026/06/Gartner-Logo-CTA-Awards.svg) A Gartner® Magic Quadrant Leader™

 ![Forrester](https://checkmarx.com/wp-content/uploads/2026/06/Forrester.svg) A Forrester Wave Leader™

 ![SOC2 Logo](https://checkmarx.com/wp-content/uploads/2026/06/SOC2-Logo.svg) SOC 2 Type II Certified

Customer Stories

## Why the World’s Top Teams Choose Checkmarx

 ![](https://checkmarx.com/wp-content/uploads/2026/05/BestBuyLogoReversedRGB-1.svg)

> “We’ve seen an 80% noise reduction — our engineers now focus on the high-quality risks that matter.”

 [ Explore Best Buy Case Study    ](https://checkmarx.com/resources/best-buy/)

 ![](https://checkmarx.com/wp-content/uploads/2025/09/Checkmarx-Best-Buy-Testimonial-V2.webp)

  ![](https://checkmarx.com/wp-content/uploads/2026/05/logo_gartner_peer_insights_3x.webp)

> “By far the best AppSec tooling decision we have made”

   ![](https://checkmarx.com/wp-content/uploads/2026/05/logo_cebu_pacific_3x.webp)

> “Checkmarx gave us a 90% reduction in vulnerabilities in just a few months.”

   ![](https://checkmarx.com/wp-content/uploads/2026/05/logo_software_ag_3x.webp)

> “Unifying our AppSec tools with Checkmarx gave us a single source of truth.”

   ![](https://checkmarx.com/wp-content/uploads/2026/05/logo_best_buy_3x.webp)

> “With 2.1B lines of code scanned monthly, Checkmarx gives us the scale and speed we need.”

   ![](https://checkmarx.com/wp-content/uploads/2026/05/logo_trade_van_3x.webp)

> “Checkmarx fits seamlessly into our DevOps pipelines—it’s a truly scalable solution.”

   ![](https://checkmarx.com/wp-content/uploads/2026/05/IDC.svg)

> “From a buyer perspective, Checkmarx’s approach offers a structured and role-aware entry point into agentic security. ”

   ![](https://checkmarx.com/wp-content/uploads/2026/05/logo_dell_3x.webp)

> “Incorporating Checkmarx’s technology has revolutionized our development culture ”

   ![](https://checkmarx.com/wp-content/uploads/2026/05/logo_gartner_peer_insights_3x.webp)

> “Checkmarx One made our security team and developers life easier.”

   ![](https://checkmarx.com/wp-content/uploads/2026/05/logo_allwyn_3x.webp)

> “The success of our AppSec program can be directly attributed to the tooling, processes and support provided by the Checkmarx managed services.”

   ![](https://checkmarx.com/wp-content/uploads/2026/05/IDC-1.svg)

> “Bringing ASPM context directly into the IDE reflects a forward-looking approach to prioritizing security efforts based on risk earlier in the development process.”

  Take the next step

## Related Resources

     Explore the Topic      [ Blog### Securing Your AI Supply Chain: Your AI Is Running, But You Don’t Know What It’s Doing

Understand why AI models introduce a new supply-chain blind spot, how hidden bundled code creates risk, and why traditional AppSec tools miss this scan surface.

5 min. read

  Read the Blog     ](https://checkmarx.com/ai-llm-tools-in-application-security/securing-your-ai-supply-chain-your-ai-is-running-but-you-dont-know-what-its-doing/) [ WebinarsShadow AI in the SDLC: A Practitioner Panel on Visibility, Risk, and the Road to Governed AI

  Watch now     ](https://checkmarx.com/shadow-ai-in-the-sdlc/)[ Whitepapers &amp; ReportsFuture of Application Security in the AI Era

  Read more     ](https://checkmarx.com/foa-report/)[ BlogYour SBOM Won’t Save You From AI Audits

8 min. read

  Read Now     ](https://checkmarx.com/blog/your-sbom-wont-save-you-from-ai-audits/)

    Learn the Landscape      [ Whitepaper### The Model That Wrote Your Code Can’t Secure It

Go deeper on AI model risk, governance, and the controls security teams need as AI adoption moves from experimentation into production.

  Read Now     ](https://checkmarx.com/llm-application-security-governing-ai-driven-risk/) [ Whitepapers &amp; Reports10 AI Supply Chain Risks Hiding in Your Codebase, and How to Get Ahead of Them

  Read more     ](https://checkmarx.com/resources/10-ai-supply-chain-risks-hiding-in-your-codebase/)[ Whitepapers &amp; ReportsSecuring the Self-Built Software Supply Chain

  Read more     ](https://checkmarx.com/resources/securing-the-self-built-software-supply-chain/)[ Analyst ReportsCheckmarx Named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security

  Read more     ](https://checkmarx.com/checkmarx-named-a-leader-in-the-2026-gartner-magic-quadrant-for-software-supply-chain-security/)

    Dig Into the Capabilities      [ Solution Brief### AI SCS: See Every AI Component in Your Codebase

See how Checkmarx AI Supply Chain Security automatically discovers and assesses AI components, detects AI-specific risks, and enforces governance through existing workflows

  Read Now     ](https://checkmarx.com/resources/ai-supply-chain-security/)

 AI Supply Chain Security

## Frequently Asked Questions

  QUICK LINKS

 [ ![](https://checkmarx.com/wp-content/uploads/2026/06/Documentation-Color.svg) Documentation ](https://docs.checkmarx.com/) [ ![](https://checkmarx.com/wp-content/uploads/2026/06/Resources-Color.svg) Resources ](https://checkmarx.com/resources/) [ ![](https://checkmarx.com/wp-content/uploads/2026/06/Trust-Center-Color.svg) Trust Center ](https://checkmarx.com/trust/) [ ![](https://checkmarx.com/wp-content/uploads/2026/06/Schedule-a-Demo-Color.svg) Schedule a Demo ](https://checkmarx.com/request-a-demo/) [ ![](https://checkmarx.com/wp-content/uploads/2026/06/Schedule-a-Integrations-Color.svg) Integrations ](https://checkmarx.com/why-checkmarx/integrations/)

  What is LLM Scanner?

LLM Scanner is a Checkmarx One capability that performs AI model security scanning on the code bundled inside model packages. It scans extracted Python source files and selected model artifacts, surfacing unsafe deserialization, command execution, and other risks before any model runs in production.

 What does LLM Scanner actually scan?

 It scans bundled source files and supported artifact types inside AI model packages, including Python files, notebooks, pickle-backed PyTorch artifacts, .h5 files, JSON, shell scripts, archives, and related metadata. It is designed to inspect the code and artifact layer that traditional AppSec tools miss.

 How is this different from SAST or SCA?

Traditional SAST scans your application code, and SCA evaluates packages and dependencies. LLM Scanner scans third-party code and model artifacts that arrive inside downloaded or fine-tuned AI model packages, including binary-backed files such as .pt and .pkl that normal code scanners cannot inspect.

 Is this a prompt injection or runtime LLM scanner?

No. LLM Scanner does not test prompt injection, model inference behavior, or runtime LLM outputs. It focuses on pre-runtime security scanning of bundled code and model artifacts before they are loaded into your environment.

 Does LLM Scanner work with commercial LLM APIs like OpenAI or Anthropic?

Not if there is no accessible model package or source to inspect. LLM Scanner is designed for open-source, internal, or fine-tuned models where bundled code and artifacts can be scanned from Hugging Face, Git repos, local directories, or internal registries.

 How does LLM Scanner help with AI governance?

LLM Scanner produces deterministic AI-BOM output that records model provenance, findings, and risk posture. That gives security, compliance, and executive teams evidence they can use to support AI governance and obligations under frameworks such as NIST AI RMF, the EU AI Act, and ISO 42001.

 How does it fit into existing pipelines?

LLM Scanner runs as a CI/CD-native CLI with SARIF, JSON, YAML, and text output, so teams can scan downloaded or fine-tuned models in existing ML pipelines without adding a separate security console or slowing model delivery.

 Where do LLM Scanner findings appear?

Findings surface directly inside Checkmarx One, alongside your SAST, SCA, and DAST results — the same console, same workflows, same integrations your team already uses.

 ## Secure AI Model Packages Before Runtime

See how LLM Scanner uncovers unsafe code inside AI model packages before it reaches production, catching critical AI risks early and generating AI-BOM evidence in Checkmarx One.

### Thank You!

Your Custom Demo Request is successfully sent. A member of Checkmarx Team would contact you shortly to set up your custom demo.

 ![thank you page decoration](https://checkmarx.com/wp-content/uploads/2026/05/get-a-demo-thank-you-1.webp)

Personalized LLM Scanner Demo

## Find Hidden Risk Inside Your AI Models

 #### Scan Hidden AI Model Code

Inspect bundled Python files and model artifacts before any model runs in production.

 #### Fit Your ML pipelines

Add CI/CD-native scanning with SARIF, JSON, YAML, or text output.

 #### Binary-Level Coverage

Detect pickle opcode gadget chains and Torch rebuild helpers no SAST or SCA tool can reach.

 #### Built-In AI Governance

Add scan findings to a deterministic AI-BOM to support NIST AI RMF, EU AI Act, and ISO 42001 requirements.

 #### One Platform

Findings appear in Checkmarx One alongside SAST, SCA, and DAST, for unified risk intelligence

 #### Catch High-Risk Patterns Early

Surface unsafe deserialization, command execution, and trust\_remote\_code risks early.

See It in Action

## Scan Model Packages Before They Run

AI models ship with hidden code most AppSec tools have never reviewed. LLM Scanner brings that blind spot into full view.

 [Request a Demo](#form)

 ![Gartner Logo - CTA Awards](https://checkmarx.com/wp-content/uploads/2026/06/Gartner-Logo-CTA-Awards.svg) A Gartner® Magic Quadrant Leader™

 ![Forrester](https://checkmarx.com/wp-content/uploads/2026/06/Forrester.svg) A Forrester Wave Leader™

 ![SOC2 Logo](https://checkmarx.com/wp-content/uploads/2026/06/SOC2-Logo.svg) SOC 2 Type II Certified
