Auditor Core – Enterprise security auditing engine for DevSecOps
Wraps Semgrep and Bandit with AI filtering, but hardware licensing feels restrictive.
Enterprise-grade CLI security auditing engine. 10 detection engines, mathematical SPI scoring (WSPM v2.2), HTML + JSON reports. Try free — 3 runs, no signup.
SPI scoring formula is clever but Snyk and Semgrep already cover these 10 engines.
DevSecOps teams and security engineers
Snyk · Semgrep · Trivy
The scoring uses WSPM v2.2:
SPI = 100 × e^-(Σ WeightedExposure / K)
K scales dynamically with project size. Context matters — findings in test code are weighted differently than findings in production handlers.Scanned 7 real-world AI infrastructure codebases. Raw output: ~7,600 findings. After context filtering and reachability analysis: 1 actionable finding. Sent a responsible disclosure letter.
Free demo on GitHub (3 runs, no signup, no telemetry): https://github.com/auditor-core-systems/auditor-core-demo
Wraps Semgrep and Bandit with AI filtering, but hardware licensing feels restrictive.
Interviews agents directly instead of relying on outdated security docs.
Conformance + security audits for MCP protocol before production—catches unsafe servers fast.
Yet another site auditor, but the 24h cache makes repeated checks actually usable.
AI code auditor, but Cursor, Continue, and Copilot already do this inline.
Yet another audit tool bundling Lighthouse, securityheaders.com, and basic robots.txt checks.