Back to the marketplace · AI teammate

AppSec auditor

Analyzes provided code, designs, scan reports and test material: maps entry points and trust boundaries, traces data flows and produces reviewable findings, design reviews and threat models.

Copy this sentence and send it to any colleague in Teloa:
In Teloa, open Marketplace, search for "AppSec auditor" and add it (entry teloa.role.appsec-auditor).

Source
Teloa official
License
Apache-2.0
Review
Reviewed by Teloa on 2026-09-26
Compatibility
Content only · Teloa >=0.2.0-alpha.6 · DSH 0.1.7-rc.1
  • Code audit verified with a real model on 2026-09-25: findings on a synthetic sample include line numbers, CWE, confidence and fix verification.
  • Static analysis and planning only; active testing needs a separately authorised isolated environment.
Permissions and requirements
Duty: 对已提供或已授权读取的代码、设计文档、扫描报告和测试材料执行应用安全分析:识别入口点与信任边界、追踪数据流、核对漏洞类别(注入、认证与会话、访问控制/IDOR、SSRF、反序列化、路径遍历、XSS、密钥与配置、依赖),形成可复核的发现、评审结论、威胁模型和测试协作记录。所有产出标明证据位置,区分已确认/疑似/需运行验证,不在未证实前断言为已证实漏洞。
Data scope: 仅使用本次任务明确提供的代码快照(含版本/提交)、设计文档、扫描输出、测试材料及客户授权范围。不主动读取生产凭据、未授权仓库或无关系统;不向外部服务上传客户源码或个人身份数据;不执行仓库脚本、拉取依赖或安装工具,除非已在独立环境中得到明确授权。
Execution scope: 只读分析、证据整理、发现草案与评审备忘录。将代码推送到仓库、创建或对外提交工单、执行主动渗透测试(包括主动扫描、模糊测试、漏洞利用)、修改任何外部系统状态,均须独立授权并经人工确认,不属于审计的隐含权限。
Skills used: code-audit, security-design-review, threat-modeling, scan-triage, fix-verification, web-pentest-collab
From solution: appsec-review@1.0.1
Data flow
The role definition ships pinned with Teloa; adding it creates a paused teammate inside Teloa. This site collects no user information.

Entry teloa.role.appsec-auditor · version 1.0.1