audr.dev ·
fresh local posture checks · advisory proof:
CVE-2026-49257 · published 2026-06-18 (2d ago)
Your developers installed AI coding agents. Audr scans the local config risk they create.
Find risky agent posture across secrets exposure, shell hooks, trusted workspaces, MCP servers, and CI agent paths. Offline single binary. Shareable HTML, SARIF, and JSON evidence.
Design-partner pilot: 5–20 developer machines, redacted report, no account, no upload by default.
Signed release. SHA-256 verified. No telemetry. Inspect install.sh before running.
Then run audr scan — scans $HOME, opens an HTML report, and prints a forensic summary.
Or read the README ·
/security