@talocode/auditlane
v0.1.2
Published
Local-first evidence-based security audit workflows for codebases and AI agents.
Readme
AuditLane
AuditLane is a local-first security audit workflow for codebases and AI agents. It maps likely entry points, records evidence-required findings, and writes a human review packet. It does not autonomously exploit targets or modify code.
Quickstart
npm install -g @talocode/auditlane
auditlane map .
auditlane report .auditlane map identifies likely routes, APIs, webhooks, authentication, and handler surfaces. auditlane report writes .auditlane/report.json. auditlane verify <root> <surface> <evidence...> records a finding only when reproducible evidence is supplied.
SDK
import { addFinding, createAudit, writeReport } from '@talocode/auditlane'
const audit = await createAudit('.')
const reviewed = addFinding(audit, { surface: 'src/api/auth.ts', check: 'auth review', severity: 'high', confidence: 0.8, evidence: ['tests/auth-repro.test.ts'] })
await writeReport(reviewed)MCP
Install @talocode/auditlane-mcp to expose auditlane_map and auditlane_verify as review-planning tools. The MCP server does not exploit targets or modify code.
Hosted Capability
Local AuditLane requires no credentials. Future hosted audits will use TALOCODE_API_KEY, TALOCODE_BASE_URL=https://api.talocode.site, and /v1/auditlane/*. These routes are planned, not currently available.
Development
npm install
npm test
cd python && python -m unittest discover -s testsSurfaces
| Surface | Package |
| --- | --- |
| CLI and SDK | npm i @talocode/auditlane |
| MCP | npm i -g @talocode/auditlane-mcp |
| Python | pip install talocode-auditlane |
Safety
Every finding needs reproducible evidence before entering human review. AuditLane does not execute exploits, publish findings, or remediate code automatically.
Talocode ecosystem
| Product | Package |
| --- | --- |
| AuditLane | npm i @talocode/auditlane (this repo) |
| Tera | pip install talocode-tera |
| Codra | pip install talocode-codra |
| XSearchLane | npm i @talocode/xsearchlane |
| ClipLane | npm i @talocode/cliplane-cli |
More: github.com/talocode · talocode.site · docs.talocode.site
MIT © Talocode
