Paper Information
- Author
- Zekun Wu,Seonglae Cho,Umar Mohammed,Cristian Munoz,Kleyton Costa,Xin Guan,Theo King,Ze Wang,Emre Kazim,Adriano Koshiyama
- Published
- 5-13-2025
- Updated
- 7-1-2025
- Affiliation
- Holistic AI
- Country
- United Kingdom
- Conference
Abstract
Open-source AI libraries are foundational to modern AI systems, yet they
present significant, underexamined risks spanning security, licensing,
maintenance, supply chain integrity, and regulatory compliance. We introduce
LibVulnWatch, a system that leverages recent advances in large language models
and agentic workflows to perform deep, evidence-based evaluations of these
libraries. Built on a graph-based orchestration of specialized agents, the
framework extracts, verifies, and quantifies risk using information from
repositories, documentation, and vulnerability databases. LibVulnWatch produces
reproducible, governance-aligned scores across five critical domains,
publishing results to a public leaderboard for ongoing ecosystem monitoring.
Applied to 20 widely used libraries, including ML frameworks, LLM inference
engines, and agent orchestration tools, our approach covers up to 88% of
OpenSSF Scorecard checks while surfacing up to 19 additional risks per library,
such as critical RCE vulnerabilities, missing SBOMs, and regulatory gaps. By
integrating advanced language technologies with the practical demands of
software risk assessment, this work demonstrates a scalable, transparent
mechanism for continuous supply chain evaluation and informed library
selection.