Skip to content
View audit0's full-sized avatar

Block or report audit0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
audit0/README.md

Audit AI. Your AI writes code. We prove it's safe to merge. Security audits for AI-built Next.js + Supabase apps.

Audit AI

Your AI writes code. Audit AI proves it's safe to merge.

A verified security engineer for AI-generated Next.js + Supabase apps: find the bug that lets one customer read another customer's data, reproduce it in a sandbox, propose the minimal fix, then run the same attack again to prove the fix holds.

One missing line of SQL, 39 seconds

In our demo app one table has no row level security, so anyone holding the public key reads every private note. A scan finds it, one migration closes it. The voice is synthetic; the demo is real. Also on X.

audit-ai-rls-hole-39s.mp4

From a scan to a verified fix, 54 seconds

Watch on YouTube or in the scanner README.

Solo founder plus AI coding agents, which is exactly the customer. Progress, numbers and failures are published as they happen, the unflattering ones included.

Popular repositories Loading

  1. auditai-scanner auditai-scanner Public

    Open-source deterministic security scanner for Next.js + Supabase apps: cross-tenant reads, RLS gaps, SECURITY DEFINER functions, with schema-level fix migrations. The engine behind auditai.sh.

    TypeScript 2

  2. SHILLGRAM-iOS SHILLGRAM-iOS Public

    SHILLGRAM for iPhone (beta): Telegram client based on Telegram-iOS (GPLv2). Sideload IPA in Releases.

    Swift 1

  3. audit0 audit0 Public

    Audit AI: your AI writes code, we prove it's safe to merge.

  4. demo-vulnerable-invoices demo-vulnerable-invoices Public

    Intentionally vulnerable Next.js + Supabase demo used by Audit AI to test sandbox proofs. Do not deploy.

    TypeScript

  5. auditai-playground auditai-playground Public

    Intentionally vulnerable Next.js + Supabase app for trying Audit AI end to end. Do not deploy.

    TypeScript

  6. Offload Offload Public

    Free up Mac disk space safely: verified moves to an encrypted external vault

    C#