Audit Prep

Know if your codebase is ready before the audit starts

Audit Prep by CD Security runs an automated 8-phase readiness check across your Solidity codebase and produces a scored report with actionable findings.

Built for Foundry and Hardhat projects.

Free. Open source. MIT licensed.

Run Audit Prep Free


Start the audit with the important work already done

Security audits should be spent reviewing protocol logic and finding vulnerabilities, not chasing missing tests, stale dependencies, compiler warnings, or incomplete documentation.

Audit Prep finds these issues before the audit begins, so your team can fix them before auditor time starts.

What you get


Preparation gaps identified

Missing tests, documentation gaps, dependency issues, deployment problems, and code hygiene concerns

Readiness score

A measurable 0-100 score showing how prepared the codebase is for review

Actionable findings

Concrete issues developers can address before the audit begins


8 phases. One readiness report.

Phase

What it checks

1. Test Coverage

Branch and line coverage, untested contracts, compiler warnings

2. Test Quality

Assertions, edge cases, negative tests, integration tests

3. Documentation

NatSpec coverage and stale or missing documentation

4. Code Hygiene

TODOs, console imports, pragmas, unused imports, error consistency

5. Dependencies

Outdated packages, CVEs, submodules, patched dependencies

6. Best Practices

SafeERC20, CEI, reentrancy protection, access control, upgradeability

7. Deployment

Build status, deployment scripts, verification setup, environment configuration

8. Project Docs

Architecture, trust assumptions, invariants, known issues, audit scope


Audit readiness scoring

Every phase receives a score from 0 to 100.

Score

Verdict

90-100

Audit Ready

75-89

Almost Ready

50-74

Needs Work

< 50

Not Ready

The Audit Prep score is not a security rating.
It measures preparation for a security review. It does not determine whether the protocol is secure.


Run Audit Prep

1. Install Claude Code

Audit Prep requires Claude Code.

Get Claude Code

2. Install Audit Prep

git clone https://github.com/CDSecurity/cdsecurity-skills.git ~/cdsecurity-skills
ln -s ~/cdsecurity-skills/audit-prep ~/.claude/skills/audit-prep

3. Open your Foundry or Hardhat project

Then run:

/audit-prep

Audit Prep analyzes the project across all eight phases and generates your readiness report.


Useful commands

Command

Purpose

/audit-prep

Run the complete readiness check

/audit-prep --fix

Automatically fix supported preparation issues

/audit-prep --report audit-prep-report.md

Save the report as Markdown

/audit-prep --diff main

Analyze changes relative to a branch

/audit-prep --ci --min-score 75

Use Audit Prep in CI with a minimum score

/audit-prep scan

Run optional static analysis

Individual readiness phases can also be run separately.

View full usage documentation on GitHub


Built from 200+ security audits

After 200+ audits, we kept seeing the same problems before reviews began:

  • Missing or weak tests
  • Unclear invariants
  • Incomplete architecture documentation
  • Stale dependencies
  • Compiler warnings
  • Deployment configuration issues
  • Missing project context
  • Undefined audit scope

These problems consume time that should be spent analyzing security-critical logic.

We built Audit Prep to catch them first.


Audit Prep prepares the code. It does not replace the audit.

Audit Prep checks whether the codebase, tests, documentation, dependencies, infrastructure, and project context are ready for an efficient security review.

It is not a vulnerability scanner or substitute for a professional security audit.

A high score means the project is well prepared for review, not that the code is vulnerability-free.


Your auditors should spend their time finding real security issues

Run Audit Prep before your next security review and see exactly where your codebase stands.

Run Audit Prep Free
Book a CD Security Audit

Open source. MIT licensed. Built by CD Security.