# AI Dependency Scanner — Free Tool > Paste a requirements.txt or package.json — see your AI/ML supply-chain surface. URL: [https://playciso.com/tools/ai-dependency-scanner](https://playciso.com/tools/ai-dependency-scanner) The AI Dependency Scanner reads a dependency manifest and pulls out the AI and ML libraries most inventories miss — the model runtimes (Transformers, PyTorch, vLLM), the LLM SDKs (OpenAI, Anthropic, LiteLLM), the agent and orchestration frameworks (LangChain, LangGraph, Langflow, Semantic Kernel), the vector databases, and MCP. These are your AI supply-chain attack surface, and they belong in your AIBOM. It also flags libraries tied to recent, actively-exploited vulnerabilities so you can check your version against the ones attackers are already hitting — everything runs in your browser, nothing is uploaded. ## How to use it - Paste a requirements.txt, a package.json, or a plain list of package names. - Read the detected AI/ML dependencies grouped by category, with a risk flag on any library that has a recent notable CVE. - Feed the AI components into an AIBOM and confirm each version is patched. ## FAQ ### Which AI libraries does it detect? Model runtimes (transformers, torch, tensorflow, onnxruntime, vllm, llama-cpp), LLM SDKs (openai, anthropic, cohere, litellm, google-generativeai), agent/orchestration frameworks (langchain, langgraph, llama-index, langflow, crewai, autogen, semantic-kernel, haystack), vector databases (chromadb, pinecone, weaviate, qdrant, faiss, milvus), and MCP libraries. ### Why does it flag some dependencies as risky? Several AI frameworks have had recent, actively-exploited vulnerabilities — for example Langflow (CVE-2026-0768), LiteLLM (CVE-2026-59822) and Hugging Face Transformers (CVE-2026-80047). The scanner flags those so you can verify your version is patched. ### Does it upload my manifest? No. Parsing and detection happen entirely in your browser; nothing you paste leaves the page. --- PlayCISO is a simulation-first platform for security leaders: a War Room incident simulator, a simulated PCI DSS QSA interview, board-report coaching, free security scanners, and a curated library of free courses. https://playciso.com