Scope the security audit — interactive form
Scope the security audit
Before I run the audit, five quick calls:
Five controls, one form - pick and go.
How deep should this audit go?
*
Recommended
Changed files only
Fast; exactly the pre-merge surface.
Full tree
Thorough but ~20 min.
Dependencies only
CVE sweep of the lockfile; skips first-party code.
Why
Covers the diff under review in ~2 min; the full tree re-scans code vetted last week.
Focus areas
*
Injection / eval-exec
Path traversal
Hardcoded secrets
Dependency CVEs
Model tier for the LLM pass
*
Escalation is automatic when findings need a second look.
— choose —
Cheap (Haiku)
Capable (Sonnet)
Premium (Fable 5)
Cap the report at how many findings?
*
Limit to a path (blank = whole scope)
Submit