Static pre-scan
Paste a file and get the deterministic pre-scan the installed audit runs FIRST — the danger patterns (eval, HTML sinks, injection shapes, disabled TLS, embedded keys) and the structural ones (a mutating route with no auth check, a test that asserts source text instead of behavior, a guard that is never called).
What it reads
These are lines to LOOK AT, not verdicts. A pattern match is a question; deciding whether it is real is the part a scan cannot do.
- High-signal danger patterns (eval, HTML sinks, injection shapes, TLS off, embedded credentials)
- A state-changing route whose handler calls no authorization check, while the app authorizes elsewhere
- A test that asserts the TEXT of a file instead of running anything
- A validation or authorization guard that nothing ever calls
What it does not look at
- whether any hit is a real defect — a match can be a comment, an escaped string, a placeholder, or already-safe code
- anything in the files you did not paste, which is where most real findings live
- the rest of the audit rubric — accessibility, privacy, error handling, licensing, cost, agent safety and the rest are not pattern-matchable
- runtime behavior: nothing here executes your code
- defects with no literal pattern, which is the majority of them
A starting point, not a clean bill of health
This scan looks for known risky patterns in the code you paste. Finding nothing does not mean the code has no problems: it means none of these patterns showed up. It is the first step the full vibe code audit runs before it reads your app as a whole.
Checking by hand too? The security checklist for AI-generated code walks through what to look at.