On your machine
npx github:odbd/oh-my-audit-free scan ./ Node 20+. Add --markdown for a report file, or --fail-on critical for a hard gate.
AI coding turns ideas into products in days. Payment flows, admin panels, login walls — all working on the surface. We find what AI-generated code hides — leaked keys, missing guards, invented dependencies — before your users do.
Runs on your machine or in your CI — we never receive your source. Prefer we do it for you? Upload instead.
The engine is open source under AGPL-3.0. Run it on your machine or inside your own CI and your source never leaves it — we receive nothing. It's the same engine that powers this site, so the score is identical either way.
npx github:odbd/oh-my-audit-free scan ./ Node 20+. Add --markdown for a report file, or --fail-on critical for a hard gate.
docker run --rm -v "$PWD:/src" ghcr.io/odbd/oh-my-audit-free scan /src No local setup: gitleaks, semgrep and osv-scanner ship inside the image.
- uses: odbd/oh-my-audit-free@v1
with:
fail-on: critical Runs in your own runner. No app to install, no repo access to grant, nothing sent out. Findings land in your Security tab via SARIF.
Upload a zip or connect a repo here and we run the same scan for you, then generate a shareable, printable audit report. Uploaded source is deleted after the scan.
You are not dropping code into a black box. The upload is kept private, the first pass stays limited, and the result helps you decide whether deeper review is worth paying for.
Your archive is stored as a private object with a server-generated name, then automatically deleted after 7 days. No public URL is made for the zip.
Auth, admin routes, payments, webhooks, secrets, uploads, and user data. The places fast launches usually trip over.
Free scans give you every finding with its file and fix. Buy an issued report when you need a dated document someone else can rely on.
Upload source only. Leave out generated files, dependency folders, logs, and .env or credential files.
Start with two free scans. Results show a security score, launch-risk level, and signal counts in My Page.
Your account keeps each upload, remaining scans, score history, and result emails tied to the right project.