BuildTube Preview About
Back to the feed

Turn your coding agent into a six-phase security auditor

A skill you install into an AI coding agent so that "audit this codebase" runs a structured hunt for vulnerabilities rather than one opinionated read.

It splits the work across isolated agents: one maps the architecture and the places untrusted input enters, others hunt through a coverage ledger that records what has actually been checked, and a fresh agent tries to disprove each candidate finding before it is written down. The output is machine-checkable records plus a written report. Cloudflare says this skill is the single-repository starting point its own vulnerability discovery harness grew out of.

You could use it to…

  • Ask your coding agent to audit a codebase for vulnerabilities
  • Get a mapped list of where untrusted input enters your app
  • Read a written report plus machine-checkable findings

Can I use this?

Coding assistant add-on

You'll need A coding agent that supports skills, and a codebase to audit · Setup needed

Worth knowing The findings are an AI agent’s claims about code, not a certified audit, and the design assumes some will be wrong — which is why it keeps a separate "needs validation" verdict for anything it could not resolve, with no severity attached. Running it costs whatever your agent’s model charges, and a thorough pass over a large repository is not a cheap request. MIT licence. BuildTube has not run or verified this software.

Why it's here

Not trending this week

Last seen on the GitHub trending list on 28 September 2026. It stays on BuildTube so you can still find it.

  • 25,226 people have starred it on GitHub.

Numbers checked on 6 October 2026; not refreshed since.

Behind it

See the code on GitHub

BuildTube has not run or verified this project. Everything above is written from what the creator published.

Made this?

Back to the feed