← Kris's Lab
Flare

Flare · Free tool by Kris McCabe

What's newly broken in your AI stack?

Flare checks the libraries most AI applications actually depend on for live, high-severity advisories — plus the OWASP LLM Top 10 as a permanent reference for the risks that never show up as a CVE at all.

Sync Loading advisory data…

Your exposure

Pick the packages in your AI stack — Flare checks each one for live, high-severity advisories. See what's actually wrong with them under .

Import from a lockfile or SBOM

Upload requirements.txt, package-lock.json, pyproject.toml, or a CycloneDX/SPDX JSON SBOM — Flare selects whichever AI-stack packages below are actually in it, instead of you clicking through by hand.

Parsed entirely in your browser — the file itself is never sent anywhere. Only matches against Flare's curated AI-stack list are auto-selected below; this isn't a general dependency scanner, so the rest of your file is left alone.

Not in the list? Add your own.

Looking up a custom package sends its name to OSV.dev from your browser. Nothing else leaves this page.

Loading the advisory snapshot…

Global threat map

Every package Flare watches — not just the ones in your stack above. Darker cells mean more advisories at that severity, right now. Click a package to see its advisories.

Loading the advisory snapshot…

The OWASP LLM & ASI Top 10

These are enduring risk categories, not news — they don't go stale the way a live advisory list does. Each one is flagged for whether it typically shows up as a CVE against a package you can patch, or as a property of how your application is built.