Open source · MIT · v0.10.0
llm-audit checks TypeScript and JavaScript for the 12 mistakes behind most LLM security bugs, mapped to the OWASP LLM Top 10. Then it teaches you each one with your own code, and hands you a prompt to fix it.
npx llm-audit scan
Needs the Semgrep engine once: brew install semgrep or pipx install semgrep.
At your terminal, mistakes are grouped worst first, with every place they occur.
npx llm-audit learn opens one lesson per mistake: where it is in your code, what is going on, and how someone would use it against you.
Every lesson ends in a prompt for Claude Code, Cursor, or whatever wrote the code. It already lists each file and line to change.
npx llm-audit prompt 1
Copies lesson 1's fix prompt. Add --check for a prompt that searches the rest of the project for the same mistake.
12 rules in 11 lessons. Each rule ships with a vulnerable example that must fire and a fixed one that must stay quiet, checked on every release.
#, which browsers never send to a server.npx llm-audit init installs it, with a GitHub Actions workflow.--baseline origin/main reports only new findings, so you can turn the gate on today.// llm-audit-ignore <rule> -- <why>. Without a reason it is not applied..llm-audit.json holds the policy for the hook, CI, and your terminal.Run both. Semgrep's official p/ai-best-practices is good work, but it doesn't scan TypeScript.
| llm-audit | p/ai-best-practices | |
|---|---|---|
| JS / TS rules | 12 | 0 of 27 |
| Focus | TypeScript, TSX, JavaScript | Python, config, Bash |
| Teaches the fix | Lessons and fix prompts | Rule messages |
| Runs at | Pre-commit and CI | CI |
# once
brew install semgrep
# see all twelve rules fire on bundled examples
npx llm-audit demo
# your project
npx llm-audit scan
npx llm-audit learn
# make it permanent: pre-commit hook, CI, agent skill
npx llm-audit init --skill