🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
Open Agent Exposure Scanner · free, no signup

Are you exposing an AI agent to the internet?

Point it at a host you own and it fingerprints internet-exposed agent infrastructure — control planes, model/agent runtimes (Ollama, vLLM, LocalAI), agent builders (Flowise, n8n, ComfyUI, Open WebUI), notebooks, MCP servers and unauthenticated inference APIs. It sends only read-only, unauthenticated GET requests — a fingerprint, not an exploit — and blocks private, loopback and cloud-metadata addresses. Authorized targets only.

Global exposure landscape

How many instances of common agent infrastructure are already exposed worldwide, from Shodan / Censys data. This scans no one — it reads counts those services already collected.

Loading…

What exposed agent infrastructure looks like

The 16 signatures this tool checks — default ports and why each one is a problem if it is reachable from the internet.

HighOllama· Model / agent runtime · port 11434

An exposed Ollama server accepts unauthenticated model runs and management. Anyone who can reach it can run inference on your GPU, pull or delete models, and use it as free compute — Ollama ships with no authentication by design.

Fix: Bind Ollama to 127.0.0.1 (OLLAMA_HOST=127.0.0.1:11434) or a private interface, put it behind an authenticating reverse proxy or VPN, and never expose port 11434 to the internet.

HighUnauthenticated OpenAI-compatible API· Agent / inference API · port 8000/1234/8080/80/443

An open /v1/models endpoint that lists models without a key means the inference API behind it (vLLM, LM Studio, LocalAI, a gateway, or an agent tool endpoint) answers unauthenticated requests. That is billable or GPU-backed compute anyone can drive, and often a pivot into connected tools.

Fix: Require an API key or mTLS on every /v1/* route, terminate at an authenticating gateway, and restrict network exposure. Treat a keyless model list as a finding even if generation seems disabled.

HighvLLM inference server· Model / agent runtime · port 8000

vLLM serves an OpenAI-compatible API with no built-in auth. Exposed, it is open GPU inference and a potential path to any tools the served agent can call.

Fix: Front vLLM with an authenticating proxy/gateway, require an API key, and bind it to a private network.

HighLocalAI· Model / agent runtime · port 8080

LocalAI exposes an OpenAI-compatible API and, in some configs, model management. Unauthenticated exposure is free compute for anyone and a foothold near your tooling.

Fix: Enable API keys, bind to localhost or a private interface, and place behind an authenticating reverse proxy.

MediumOpen WebUI· Agent / workflow builder · port 8080/3000

Open WebUI is a chat/agent front-end for Ollama and OpenAI-compatible backends. Exposed with open sign-up it lets strangers create accounts and drive your models and any connected tools/RAG data.

Fix: Disable open sign-up, require SSO, put it behind a VPN or authenticating proxy, and do not expose it directly to the internet.

MediumComfyUI· Agent / workflow builder · port 8188

ComfyUI runs arbitrary generation/agent workflows with no auth. Exposed, it is remotely-drivable compute; some custom nodes can read/write files or run code on the host.

Fix: Never expose ComfyUI directly; bind to localhost and reach it over a VPN or an authenticating proxy. Audit custom nodes for filesystem/exec capability.

MediumText Generation WebUI (oobabooga)· Agent / workflow builder · port 7860/5000

The WebUI and its API expose model loading and generation. With the API extension on and no auth, it is remote inference and, via some extensions, code execution.

Fix: Set a gradio auth user/password or front with an authenticating proxy, and do not expose ports 7860/5000 to the internet.

HighFlowise· Agent / workflow builder · port 3000

Flowise builds and hosts LLM agents/chains. Exposed without app-level auth, its flows, stored credentials/API keys and connected tools are reachable, and its prediction endpoints can be driven by anyone.

Fix: Enable Flowise username/password (FLOWISE_USERNAME/PASSWORD), put it behind SSO/VPN, and rotate any API keys stored in its flows if it was ever internet-exposed.

Highn8n· Agent / workflow builder · port 5678

n8n runs automation/agent workflows that often hold credentials for many third-party services. An exposed instance without auth exposes those workflows, stored credentials and webhook triggers.

Fix: Enable n8n user management/basic auth, restrict to a private network or VPN, and rotate stored credentials if it was exposed.

MediumLangServe / LangChain server· Agent / inference API · port 8000/8080

A LangServe endpoint exposes a chain/agent for invocation. Without auth, anyone can invoke it, potentially triggering the tools and data sources the chain is wired to.

Fix: Add authentication middleware in front of the runnable, restrict the playground in production, and scope the tools the chain can reach.

CriticalJupyter Notebook / Lab· Notebook / compute · port 8888

A token-less or weakly-protected Jupyter server is arbitrary code execution as the running user — the single most dangerous surface here. Agents are frequently prototyped and run inside notebooks.

Fix: Require a strong token or password, bind to localhost, and reach notebooks only over SSH tunnel or VPN. Never expose port 8888 to the internet.

CriticalRay dashboard / Jobs API· Supporting infrastructure · port 8265

The Ray Jobs API accepts unauthenticated job submission — an exposed dashboard is remote code execution across the cluster. Ray is a common backend for distributed agent/LLM workloads.

Fix: Never expose the Ray dashboard/Jobs API; put it behind authentication and a private network. Treat any internet exposure as a compromise-grade finding.

MediumGradio app (generic)· Agent / workflow builder · port 7860

Gradio is the front-end for many ML/agent demos. Exposed apps can be driven by anyone; some expose file components or arbitrary function endpoints.

Fix: Set auth=("user","pass") on launch or front with an authenticating proxy; avoid share=True in production; do not expose port 7860 publicly.

MediumChroma vector database· Supporting infrastructure · port 8000

An exposed vector DB is your RAG corpus — often sensitive internal documents and embeddings — readable and writable by anyone, and poisonable to manipulate downstream agents.

Fix: Enable Chroma auth, bind to a private network, and never expose the API to the internet. Review what documents were embedded if it was exposed.

HighOpenClaw Enterprise control plane· Agent control plane · port 443/80/8080

A persistent-agent control plane governs long-running agents, their tools and their credentials. An exposed or weakly-authenticated control plane is high-value: it can list, create and drive agents with access to internal systems. (Signature is a best-effort name heuristic for a newly released platform — verify manually.)

Fix: Keep any agent control plane on a private network behind SSO/mTLS, enforce least-privilege on agent tool scopes, and rotate agent credentials if the plane was ever reachable from the internet.

HighModel Context Protocol (MCP) server· Agent / inference API · port 8080/3000/8000

An exposed MCP server offers tools and resources to any client that connects. Unauthenticated, its tools (file access, shell, database, SaaS) are callable by strangers — the classic "agent tool access" risk.

Fix: Require auth on the MCP transport, scope tools to least privilege, and audit exposed servers. For a deep MCP-specific scan, use PlayCISO’s dedicated MCP Scan.

Going deeper: for a full Model Context Protocol scan of a specific server (tools, resources, unauth checks), use the MCP Scan. To govern refusal-removed open models running inside your environment, see the Abliterated Model Risk Calculator and Model Risk Scanner. Context on the agent-control-plane trend is in our AI Lab Security Tracker.

Authorized-target only. This tool performs non-intrusive, unauthenticated GET fingerprinting and refuses private/internal addresses. It is a defensive self-assessment aid, not a guarantee of coverage or safety.

Open Agent Exposure Scanner — Find Exposed AI Agents & Runtimes (Free) · PlayCISO