LibVulnWatch: A Deep Assessment Agent System and Leaderboard for Uncovering Hidden Vulnerabilities in Open-Source AI Libraries

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wu, Zekun, Cho, Seonglae, Mohammed, Umar, Munoz, Cristian, Costa, Kleyton, Guan, Xin, King, Theo, Wang, Ze, Kazim, Emre, Koshiyama, Adriano
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918075781087232
author Wu, Zekun
Cho, Seonglae
Mohammed, Umar
Munoz, Cristian
Costa, Kleyton
Guan, Xin
King, Theo
Wang, Ze
Kazim, Emre
Koshiyama, Adriano
author_facet Wu, Zekun
Cho, Seonglae
Mohammed, Umar
Munoz, Cristian
Costa, Kleyton
Guan, Xin
King, Theo
Wang, Ze
Kazim, Emre
Koshiyama, Adriano
contents Open-source AI libraries are foundational to modern AI systems, yet they present significant, underexamined risks spanning security, licensing, maintenance, supply chain integrity, and regulatory compliance. We introduce LibVulnWatch, a system that leverages recent advances in large language models and agentic workflows to perform deep, evidence-based evaluations of these libraries. Built on a graph-based orchestration of specialized agents, the framework extracts, verifies, and quantifies risk using information from repositories, documentation, and vulnerability databases. LibVulnWatch produces reproducible, governance-aligned scores across five critical domains, publishing results to a public leaderboard for ongoing ecosystem monitoring. Applied to 20 widely used libraries, including ML frameworks, LLM inference engines, and agent orchestration tools, our approach covers up to 88% of OpenSSF Scorecard checks while surfacing up to 19 additional risks per library, such as critical RCE vulnerabilities, missing SBOMs, and regulatory gaps. By integrating advanced language technologies with the practical demands of software risk assessment, this work demonstrates a scalable, transparent mechanism for continuous supply chain evaluation and informed library selection.
format Preprint
id arxiv_https___arxiv_org_abs_2505_08842
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle LibVulnWatch: A Deep Assessment Agent System and Leaderboard for Uncovering Hidden Vulnerabilities in Open-Source AI Libraries
Wu, Zekun
Cho, Seonglae
Mohammed, Umar
Munoz, Cristian
Costa, Kleyton
Guan, Xin
King, Theo
Wang, Ze
Kazim, Emre
Koshiyama, Adriano
Cryptography and Security
Computation and Language
Open-source AI libraries are foundational to modern AI systems, yet they present significant, underexamined risks spanning security, licensing, maintenance, supply chain integrity, and regulatory compliance. We introduce LibVulnWatch, a system that leverages recent advances in large language models and agentic workflows to perform deep, evidence-based evaluations of these libraries. Built on a graph-based orchestration of specialized agents, the framework extracts, verifies, and quantifies risk using information from repositories, documentation, and vulnerability databases. LibVulnWatch produces reproducible, governance-aligned scores across five critical domains, publishing results to a public leaderboard for ongoing ecosystem monitoring. Applied to 20 widely used libraries, including ML frameworks, LLM inference engines, and agent orchestration tools, our approach covers up to 88% of OpenSSF Scorecard checks while surfacing up to 19 additional risks per library, such as critical RCE vulnerabilities, missing SBOMs, and regulatory gaps. By integrating advanced language technologies with the practical demands of software risk assessment, this work demonstrates a scalable, transparent mechanism for continuous supply chain evaluation and informed library selection.
title LibVulnWatch: A Deep Assessment Agent System and Leaderboard for Uncovering Hidden Vulnerabilities in Open-Source AI Libraries
topic Cryptography and Security
Computation and Language
url https://arxiv.org/abs/2505.08842