LocalAudit

Security · 100% local

Learn

Rule catalog

Every detection rule in the scanner — 77 in total — with its severity and CWE/OWASP mapping. Use it to understand what each finding means and to teach a checklist.

Critical

Hardcoded private key block

Any file · secret-private-key

CWE-798OWASP A07:2021
Critical

Hardcoded aWS access key ID

Any file · secret-aws-access-key

CWE-798OWASP A07:2021
Critical

Hardcoded aWS secret access key

Any file · secret-aws-secret-key

CWE-798OWASP A07:2021
Critical

Hardcoded gitHub token

Any file · secret-github-token

CWE-798OWASP A07:2021
Critical

Hardcoded gitLab personal access token

Any file · secret-gitlab-token

CWE-798OWASP A07:2021
Critical

Hardcoded slack token

Any file · secret-slack-token

CWE-798OWASP A07:2021
Medium

Hardcoded slack incoming webhook

Any file · secret-slack-webhook

CWE-798OWASP A07:2021
Critical

Hardcoded stripe live secret key

Any file · secret-stripe-live-key

CWE-798OWASP A07:2021
Medium

Hardcoded google API key

Any file · secret-google-api-key

CWE-798OWASP A07:2021
Critical

Hardcoded anthropic API key

Any file · secret-anthropic-api-key

CWE-798OWASP A07:2021
Critical

Hardcoded openAI API key

Any file · secret-openai-api-key

CWE-798OWASP A07:2021
Critical

Hardcoded npm access token

Any file · secret-npm-token

CWE-798OWASP A07:2021
Critical

Hardcoded sendGrid API key

Any file · secret-sendgrid-key

CWE-798OWASP A07:2021
Critical

Hardcoded credentials embedded in connection URL

Any file · secret-credentials-in-url

CWE-798OWASP A07:2021
Medium

Hardcoded jSON Web Token

Any file · secret-jwt

CWE-798OWASP A07:2021
Medium

Hardcoded hardcoded secret assignment

Any file · secret-generic-secret

CWE-798OWASP A07:2021
Critical

Missing Strict-Transport-Security header

vercel.json · vercel-strict-transport-security

CWE-319OWASP A05:2021
Critical

Missing Content-Security-Policy header

vercel.json · vercel-content-security-policy

CWE-693OWASP A03:2021
Medium

Missing X-Frame-Options header

vercel.json · vercel-x-frame-options

Medium

Missing X-Content-Type-Options header

vercel.json · vercel-x-content-type-options

Low

Missing Referrer-Policy header

vercel.json · vercel-referrer-policy

Low

Missing Permissions-Policy header

vercel.json · vercel-permissions-policy

OWASP A05:2021
Varies

Permissive Content-Security-Policy

vercel.json · vercel-weak-csp

CWE-693OWASP A03:2021
Low

HSTS max-age shorter than 180 days

vercel.json · vercel-short-hsts

Varies

Wildcard CORS origin

vercel.json · vercel-cors-wildcard

CWE-942OWASP A05:2021
Low

X-Powered-By discloses the stack

vercel.json · vercel-x-powered-by

Critical

Dependency below known-safe version

package.json · pkg-vuln*

OWASP A06:2021
Critical

Known compromised release (hijacked maintainer)

package.json · pkg-compromised*

CWE-506OWASP A08:2021
Critical

Known malicious or typosquat package

package.json · pkg-malicious*

CWE-506OWASP A08:2021
Critical

Dependency downloaded over plain HTTP

package.json · pkg-insecure-source*

Medium

Dependency installed from git/URL

package.json · pkg-non-registry*

CWE-494OWASP A08:2021
Medium

Unbounded version range

package.json · pkg-unbounded-range*

CWE-1357OWASP A06:2021
Critical

Install hook downloads or evaluates code

package.json · pkg-suspicious*

Medium

Dev tool shipped in production dependencies

package.json · pkg-devtool-in-deps*

Low

No audit script

package.json · pkg-missing-audit-script

Critical

Container runs as root

Dockerfile · docker-root-user

CWE-250CIS Docker 4.1
Medium

Unpinned base image

Dockerfile · docker-latest-tag

Critical

Secret baked into image via ENV

Dockerfile · docker-secret-env*

Medium

Secret recorded in image history via ARG

Dockerfile · docker-secret-arg*

Medium

ADD from URL without checksum

Dockerfile · docker-add-remote*

CWE-494OWASP A08:2021
Medium

Remote script piped into a shell

Dockerfile · docker-curl-pipe-shell*

CWE-494OWASP A08:2021
Medium

World-writable permissions

Dockerfile · docker-chmod-777*

Low

sudo used in build

Dockerfile · docker-sudo*

Medium

SSH port exposed

Dockerfile · docker-expose-ssh

Low

COPY . copies the whole build context

Dockerfile · docker-copy-all

Low

No HEALTHCHECK

Dockerfile · docker-no-healthcheck

CIS Docker 4.6
Critical

.env files not ignored

.gitignore · gitignore-missing-env

Medium

Private key files not ignored

.gitignore · gitignore-missing-keys

Critical

Negation re-includes an env file

.gitignore · gitignore-env-negated

Low

Credential files not ignored

.gitignore · gitignore-missing-sensitive

Low

node_modules not ignored

.gitignore · gitignore-missing-node-modules

Critical

Server secret behind a public prefix

.env · env-client-exposed*

CWE-200OWASP A01:2021
Critical

Default or weak credential

.env · env-weak-credential*

Medium

Signing secret shorter than 32 characters

.env · env-short-signing-secret*

Medium

Debug mode enabled

.env · env-debug*

Critical

TLS certificate verification disabled

.env · env-tls-verification-disabled

Medium

TLS disabled for a connection

.env · env-db-ssl-disabled*

Low

Plain-HTTP endpoint

.env · env-plain-http*

Medium

Wildcard CORS origin

.env · env-cors-wildcard*

Critical

Privileged container

docker-compose.yml · compose-privileged*

CWE-250CIS Docker 5.4
Critical

Docker socket mounted

docker-compose.yml · compose-docker-socket*

CWE-668CIS Docker 5.31
Critical

Sensitive host path mounted

docker-compose.yml · compose-sensitive-mount*

CWE-668CIS Docker 5.5
Medium

Host namespace shared

docker-compose.yml · compose-host*

CWE-653CIS Docker 5.9
Medium

Seccomp/AppArmor/SELinux disabled

docker-compose.yml · compose-unconfined*

CWE-693CIS Docker 5.21
Varies

Dangerous Linux capability added

docker-compose.yml · compose-cap*

CWE-250CIS Docker 5.3
Varies

Database port published on all interfaces

docker-compose.yml · compose-public-datastore*

Critical

Default database password

docker-compose.yml · compose-weak-password*

Low

Unpinned service image

docker-compose.yml · compose-unpinned-image*

Critical

Deprecated TLS protocol enabled

nginx.conf · nginx-weak-tls*

CWE-327OWASP A02:2021
Critical

Weak cipher suites allowed

nginx.conf · nginx-weak-ciphers*

CWE-327OWASP A02:2021
Critical

Alias off-by-slash path traversal

nginx.conf · nginx-alias-traversal*

CWE-22OWASP A01:2021
Medium

Directory listing enabled

nginx.conf · nginx-autoindex

Low

HTTP not redirected to HTTPS

nginx.conf · nginx-no-https-redirect

Medium

Plain HTTP only

nginx.conf · nginx-no-https

CWE-319OWASP A02:2021
Medium

Wildcard CORS origin

nginx.conf · nginx-cors-wildcard*

Varies

Missing security headers

nginx.conf · nginx-missing-security-headers

OWASP A05:2021
Low

nginx version advertised

nginx.conf · nginx-server-tokens