> For the complete documentation index, see [llms.txt](https://docs.opsmx.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.opsmx.com/code-to-cloud-security-and-scanners/ai-security/how-to-do-a-model-scan.md).

# How to do a Model Scan

The AI Model scan option is added as part of the Adhoc scan. The ability to scan AI/ML Models published on HuggingFace using NBDefence and Garak tools is added as part of this scan option. This gives teams visibility into AI components, their dependencies, and lifecycle details (including versioning), while capturing all mandatory metadata fields.

### To Access Model Scan&#x20;

* Navigate to **Scan Now** > **Model Scan**.

<figure><img src="/files/nruRo2clCcd9cLv3OmKm" alt=""><figcaption></figcaption></figure>

### To Add a Project&#x20;

* Navigate to Scan Now > Source Scan.
* Click Add Project. In the Create Project page, enter the following details:

<img src="/files/Bx2gFo1VElRHYDWTd9XM" alt="" height="261" width="573">

* Name : Enter a name for the project.
* Team : Select the team for which you want to create the project.
* Scan Type : The default type is Source Scan.
* Platform : Select the platform type, the platform where the code resides (Github, Gitlab Server, Bitbucket, Bitbucket Server, Azure, Azure Server) for the project.
* Account : Choose the AI-BOM account that you have added.&#x20;
* Organization / Workspace : Choose the organization or workspace that the selected account has access to.
* Scan Level : Select the scan level; either organization level or repository level that needs to be scanned.
* Configuration : Set the configuration details, and schedule the auto scan time.
* Repo /Project : Select the repo or project name for which the scan needs to be executed.
* Branch :  Select the branch name for which the scan needs to be executed.
* Branch Pattern : Select the branch pattern for which the scan needs to be executed.
* Code Path : The specific directory or file path within the repository that the scanner should analyze.
* Provider Name : The Artificial Intelligence provider being used to perform the analysis. The dropdown includes options like Anthropic, Google, IBM, Meta, and OpenAI.
* Model Name : The specific AI model from the chosen provider that will execute the scan (e.g., Claude Fable 5).
* Scan Upto : Select the branch limit for which the scan needs to be executed. (number of branches to be scanned)
* Schedule Auto Scan :  Select the time range during which the scan needs to be rerun automatically.
* Click Save.

The project gets added for scanning.

### To Upload a Project

* To upload a project from your local, for scanning, click **Upload Project**.

<figure><img src="/files/HcMI4eAfLkeIYqbBlKVb" alt=""><figcaption></figcaption></figure>

* Click **Upload File** and select the json file that you want to add for scanning. &#x20;

<figure><img src="/files/IpQviTCNIyjgVQt5Iedm" alt=""><figcaption></figcaption></figure>

* Click **Save**.&#x20;

<figure><img src="/files/HDdpi87rWfnLEfu6M0bs" alt=""><figcaption></figcaption></figure>

The file gets added for scanning.

### To Integrate JIRA at Project Level

JIRA can be integrated at project level to create tickets whenever an alert is identified.&#x20;

* To integrate JIRA, click the Integrations icon on expanding the project.&#x20;

<figure><img src="/files/D87SrN8JKJlZ7rfSXbON" alt=""><figcaption></figcaption></figure>

* The JIRA integration page is displayed. Click **Add Account** and enter the details.&#x20;

<figure><img src="/files/zfsM6BarJXhWpjlfjjR2" alt=""><figcaption></figcaption></figure>

* Enter the values for the following fields:
  * **Account Name -** Enter the JIRA account name.&#x20;
  * **Jira Project Key -** Enter the name of your Jira project.&#x20;
  * **Jira** **URL -** Enter your Jira host Url&#x20;
  * **Jira Email Id -** Enter the username to access Jira.&#x20;
  * **Token -** Enter the password / token for the Jira account.&#x20;
  * Enable **Automatically create Jira tickets during the scan** to create JIRA ticket to the team owner when the alerts are identified.&#x20;
  * **Trigger Type** - Indicates at which level Jira tickets should be created.&#x20;
    * **Create Jira ticket at the Component Alert level** - Jira tickets will be created for each individual impacted component.&#x20;
    * **Create Jira ticket at the Deduplication Alert level** -  A single Jira ticket will be created for all the impacted components.&#x20;
    * **Creation Scope** - If Vulnerabilities is selected, Jira is created only for Critical and High alerts. If All Policies is selected Jira is created for all alerts.&#x20;
  * Enable **Assign the Jira ticket to the Team owner** if you want to assign the ticket to the team owner.&#x20;
  * **Fields -** Enter the labels that need to be added in the created Jira ticket.&#x20;
  * **Values -** Enter the values that need to be given in the Jira ticket. The given variables are replaced with actual values when the tickets are created.&#x20;
  * **Status Keyword Mapping** - You can set the keywords for the status.&#x20;
* Click **Test** to check if the entered values are valid.
* Once validated, click **Save**. The tool is connected.

### To View AI-Based Remediation Details

AI Remediation is integrated in the Scan Now option.&#x20;

1. Expand the project for which you want to view the remediation details.&#x20;
2. Click **Open Issues** to view the list of alerts.&#x20;

<figure><img src="/files/81Yfo5MHt22pqUQHq4oq" alt=""><figcaption></figcaption></figure>

3. From the alerts list, select the required alert.

<figure><img src="/files/CfxUuwD4p6lXBvtZD6Ze" alt=""><figcaption></figcaption></figure>

4. Navigate to the **Impacted Components** section and click on it.
5. In the list of applications, identify the relevant application and click **Remediate**.

<figure><img src="/files/WBeNueu8GkfIXl93QYVa" alt=""><figcaption></figcaption></figure>

The AI Remediation window is displayed. It analyzes the selected alert and provides a detailed summary of the issue, recommended remediation steps and possible workarounds.&#x20;

<figure><img src="/files/4CuuUFztzaA7F711TXEv" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
AI Remediation is supported only for repositories hosted on GitHub Cloud. Remediation is performed only when the source details of the associated artifacts or projects are available.
{% endhint %}

### To View and Interpret Scan Results&#x20;

Once the scan is complete, OpsMx generates the overall results and they are displayed as shown below: <br>

* Repos Registered
* Total Branches
* Total Scans
* Total Projects
* Auto Scan Enabled Repos

<figure><img src="/files/5iT3oTn1kbuRTpTORhYh" alt=""><figcaption></figcaption></figure>

The panel at the bottom displays the project details. On expanding each project you can view the complete details of it.

{% hint style="info" %}
The current status of the scan (completed, pending or failed) is displayed to notify the status of the project.&#x20;
{% endhint %}

* To edit the configuration details of the project, click the **Edit Configuration** button.&#x20;
* Click the **View** option in the **Action** button, to view the SAST and SCA scan results of the project.&#x20;

<figure><img src="/files/Trxwxmlwnn0xW4wx9XCO" alt=""><figcaption></figcaption></figure>

* The results page displays the complete data of the scan details.&#x20;
  * On clicking the **Download** button, the scan results are downloaded in .json or .csv format.
  * On clicking **Report**, the scan results are downloaded in a report format.&#x20;
  * On clicking **Go to Artifact** Page, you are redirected to the [Model Scan Artifact](https://docs.opsmx.com/code-to-cloud-security-and-scanners/artifact-security/model-scan-artifacts) page.&#x20;

<figure><img src="/files/xYGeD7FNoEyXFmUtpAQW" alt=""><figcaption></figcaption></figure>
