Security Auditor
$49
Premium tier
Runs a multi-pass sweep for secrets, injection, and broken authorization, and reports evidence-backed findings with honest coverage limits. Read-only.
How it runs
5-step pipelineself-check gateyour approval
model proposespolicy validatesexecutor runs
The model never touches your system directly. Every tool call is checked against security.yaml first.
What it can touch
- read files
- ripgrep / grep patterns
- git history
- read-only — it never writes or sends
Guarantees
Read-onlyEvidence-backedHonest coverage limitsLangGraph state machinePython + TypeScriptSecurity-policy enforcedModel-agnosticSelf-evaluating output