Project overview
secauditor examines a codebase without editing source or running exploits, scoring up to eleven security dimensions against OWASP, CWE, SLSA, and relevant NIST guidance. It writes a self-contained secaudit.md with exact file locations, source-to-sink paths, preconditions, impact, a specific fix, and a way to verify the change. Conditional dimensions are omitted when a project has no matching surface, and the audit looks for controls that exist only on paper. It runs in Claude Code or Codex.
Repository facts
- Primary language
- Not detected
- License
- MIT
- Repository updated
- Jul 5, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacy
Platforms
Claude Code, Codex, and more
Capabilities
Verification and evals