Know if your codebase is ready before the audit starts
Audit Prep by CD Security runs an automated 8-phase readiness check across your Solidity codebase and produces a scored report with actionable findings.
Built for Foundry and Hardhat projects.
Free. Open source. MIT licensed.
Start the audit with the important work already done
Security audits should be spent reviewing protocol logic and finding vulnerabilities, not chasing missing tests, stale dependencies, compiler warnings, or incomplete documentation.
Audit Prep finds these issues before the audit begins, so your team can fix them before auditor time starts.
What you get | |
|---|---|
Preparation gaps identified | Missing tests, documentation gaps, dependency issues, deployment problems, and code hygiene concerns |
Readiness score | A measurable 0-100 score showing how prepared the codebase is for review |
Actionable findings | Concrete issues developers can address before the audit begins |
8 phases. One readiness report.
Phase | What it checks |
|---|---|
1. Test Coverage | Branch and line coverage, untested contracts, compiler warnings |
2. Test Quality | Assertions, edge cases, negative tests, integration tests |
3. Documentation | NatSpec coverage and stale or missing documentation |
4. Code Hygiene | TODOs, console imports, pragmas, unused imports, error consistency |
5. Dependencies | Outdated packages, CVEs, submodules, patched dependencies |
6. Best Practices | SafeERC20, CEI, reentrancy protection, access control, upgradeability |
7. Deployment | Build status, deployment scripts, verification setup, environment configuration |
8. Project Docs | Architecture, trust assumptions, invariants, known issues, audit scope |
Audit readiness scoring
Every phase receives a score from 0 to 100.
Score | Verdict |
|---|---|
90-100 | Audit Ready |
75-89 | Almost Ready |
50-74 | Needs Work |
< 50 | Not Ready |
The Audit Prep score is not a security rating.
It measures preparation for a security review. It does not determine whether the protocol is secure.
Run Audit Prep
1. Install Claude Code
Audit Prep requires Claude Code.
2. Install Audit Prep
git clone https://github.com/CDSecurity/cdsecurity-skills.git ~/cdsecurity-skills
ln -s ~/cdsecurity-skills/audit-prep ~/.claude/skills/audit-prep
3. Open your Foundry or Hardhat project
Then run:
/audit-prepAudit Prep analyzes the project across all eight phases and generates your readiness report.
Useful commands
Command | Purpose |
|---|---|
| Run the complete readiness check |
| Automatically fix supported preparation issues |
| Save the report as Markdown |
| Analyze changes relative to a branch |
| Use Audit Prep in CI with a minimum score |
| Run optional static analysis |
Individual readiness phases can also be run separately.
View full usage documentation on GitHub
Built from 200+ security audits
After 200+ audits, we kept seeing the same problems before reviews began:
- Missing or weak tests
- Unclear invariants
- Incomplete architecture documentation
- Stale dependencies
- Compiler warnings
- Deployment configuration issues
- Missing project context
- Undefined audit scope
These problems consume time that should be spent analyzing security-critical logic.
We built Audit Prep to catch them first.
Audit Prep prepares the code. It does not replace the audit.
Audit Prep checks whether the codebase, tests, documentation, dependencies, infrastructure, and project context are ready for an efficient security review.
It is not a vulnerability scanner or substitute for a professional security audit.
A high score means the project is well prepared for review, not that the code is vulnerability-free.
Your auditors should spend their time finding real security issues
Run Audit Prep before your next security review and see exactly where your codebase stands.
Run Audit Prep Free
Book a CD Security Audit
Open source. MIT licensed. Built by CD Security.