secauditor
Run a read-only, prioritized security audit across a codebase
- Stars
- 1
- Forks
- 0
- Updated
- Updated Jul 5, 2026
Run a read-only, prioritized security audit across a codebase
secauditor examines a codebase without editing source or running exploits, scoring up to eleven security dimensions against OWASP, CWE, SLSA, and relevant NIST guidance. It writes a self-contained secaudit.md with exact file locations, source-to-sink paths, preconditions, impact, a specific fix, and a way to verify the change. Conditional dimensions are omitted when a project has no matching surface, and the audit looks for controls that exist only on paper. It runs in Claude Code or Codex.
Resource types
Use cases
Platforms
Capabilities
Audit suspension risks in a Claude Code working environment.
Check whether a specific CVE actually applies to your environment.
Public GitHub facts last synced Jul 10, 2026.
Store and inject development secrets through 1Password from Claude Code.
Audit a deployed public app for production gaps missed during coding.