Open source · MIT · v0.10.0

Find the security holes AI writes into your LLM app.

llm-audit checks TypeScript and JavaScript for the 12 mistakes behind most LLM security bugs, mapped to the OWASP LLM Top 10. Then it teaches you each one with your own code, and hands you a prompt to fix it.

npx llm-audit scan

Needs the Semgrep engine once: brew install semgrep or pipx install semgrep.

UntrustedPrivileged request.json()system prompt retrieved docseval · innerHTML model outputtool dispatch
Every rule is one idea: untrusted text must not arrive with privileged authority.

Scan

At your terminal, mistakes are grouped worst first, with every place they occur.

Terminal recording of npx llm-audit scan: three mistakes in a chat route handler, each with its file and line, ending with the commands to read the lessons and copy a fix prompt

Learn

npx llm-audit learn opens one lesson per mistake: where it is in your code, what is going on, and how someone would use it against you.

The lessons page for a sample support bot: 7 mistakes in 9 places, a numbered contents list, and lesson 1 showing the flagged lines

Fix

Every lesson ends in a prompt for Claude Code, Cursor, or whatever wrote the code. It already lists each file and line to change.

npx llm-audit prompt 1

Copies lesson 1's fix prompt. Add --check for a prompt that searches the rest of the project for the same mistake.

A lesson's attack walkthrough and its fix prompt

What it catches

12 rules in 11 lessons. Each rule ships with a vulnerable example that must fire and a fixed one that must stay quiet, checked on every release.

Your code stays put

  • Runs on your machine. The scan is Semgrep with llm-audit's rules, offline. No account, no upload, no telemetry.
  • The lessons page is a static file. Its security policy blocks every network request. A share link carries the results after the #, which browsers never send to a server.
  • Secrets are redacted in every output that shows code: terminal, JSON, HTML, and lessons.
  • No dependencies. Nothing extra in your supply chain, and every release is published from CI with signed provenance.

Ready for real repos

Pre-commit hook
Scans only staged files. npx llm-audit init installs it, with a GitHub Actions workflow.
Pull request annotations
In GitHub Actions, findings appear on the changed lines, with a summary on the job page.
Baseline
--baseline origin/main reports only new findings, so you can turn the gate on today.
Ignores need a reason
// llm-audit-ignore <rule> -- <why>. Without a reason it is not applied.
One config file
.llm-audit.json holds the policy for the hook, CI, and your terminal.
Every format
Versioned JSON for agents, SARIF for code scanning, a standalone HTML report.

Why not Semgrep's AI pack?

Run both. Semgrep's official p/ai-best-practices is good work, but it doesn't scan TypeScript.

llm-auditp/ai-best-practices
JS / TS rules120 of 27
FocusTypeScript, TSX, JavaScriptPython, config, Bash
Teaches the fixLessons and fix promptsRule messages
Runs atPre-commit and CICI

Start

# once
brew install semgrep

# see all twelve rules fire on bundled examples
npx llm-audit demo

# your project
npx llm-audit scan
npx llm-audit learn

# make it permanent: pre-commit hook, CI, agent skill
npx llm-audit init --skill