Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
CrowdStrike claims discovery of local models, Model Context Protocol (MCP) servers, integrated development environment (IDE) extensions, misconfigured AI tooling, vulnerabilities, and supply-chain risks on engineering endpoints before exploitation.
This helps security and engineering teams identify supply chain risks and misconfigured AI tooling before they become exploitable vulnerabilities.
Related framework references (5)