OAuth App Risk Scanner

Rule-based analysis · RAG breach knowledge base · Claude fallback (low-confidence only)

Deterministic rules (primary)RAG breach KB (… vendor records)Claude fallback (low-confidence only)
Analyze an OAuth App
How Detection Works
Rule Engine (always runs)

Scope risk scored deterministically using a static risk table covering 50+ Microsoft Graph, GitHub, Vercel, Slack, and Google scopes. No AI needed, no API calls, instant.

RAG Knowledge Base

App/vendor name is searched against a Supabase table of 12+ known breach records (SolarWinds, CircleCI, Context AI…). Full-text search — no embeddings, no LLM.

Claude Fallback

Only fires when both rule engine and KB return low confidence — unknown vendor, unknown scopes. Claude gets the KB context + scope list and returns a plain-English assessment.