Skip to main content

OSE Auditor

OSE Auditor is an autonomous financial and logic exploit detection engine for Node.js and TypeScript backends. It uses deterministic code analysis combined with AI-powered remediation to surface money-losing vulnerabilities before they reach production.

It catches what generic AI models and traditional SAST tools miss: broken authorization gates on financial mutations, double-spend race conditions, unchecked external payment calls, privilege escalation via user-controlled roles, invalid order lifecycle transitions, and more.


Why OSE Auditor?

Most SAST tools find injection and XSS. OSE Auditor finds the bugs that drain your users' money:

  • A payment route that processes charges without verifying the caller is authenticated
  • A withdrawal endpoint where two concurrent requests can both read the same pre-deducted balance
  • A Stripe call whose result is never checked before balance is decremented
  • An order marked completed before payment has confirmed
  • A role check that reads req.body.role — set by the attacker

These bugs are invisible to linters, missed by code review, and never caught in unit tests because they require reasoning about ordering, ownership, and financial semantics across an entire function's control flow.


Quick Start

# Install (pipx recommended — isolated, no PEP 668 conflicts)
pipx install ose-auditor

# Create a free account
ose signup

# Audit your project
ose audit ./your-nodejs-project

# Buy more credits when you need them
ose buy

Or with npm/npx — zero Python setup required:

npm install -g ose-auditor
ose audit ./your-nodejs-project

# or without installing
npx ose-auditor audit ./your-nodejs-project

How It Works

OSE Auditor runs a three-stage pipeline entirely on your machine before any data leaves:

  1. Parser — walks your project, strips comments, computes hashes, assembles a normalized source index (Contract A). Open-source, stdlib-only, no network I/O.

  2. Financial Semantic Analyzer (FSA) — parses every JavaScript/TypeScript file into an AST using tree-sitter, builds a per-function state transition graph (validation nodes, external-call nodes, state-mutation nodes, in source order), then applies deterministic vulnerability signatures. No AI, no false-positive lottery — rules are hardcoded and auditable. The FSA core is compiled and proprietary; the client layer that calls it is MIT-licensed.

  3. Patch Generation (OSE Server) — if the FSA finds vulnerabilities, the manifest is sent to the OSE Server, which calls a configurable LLM (Claude, GPT-4, or Groq) with track-specific few-shot prompts to generate production-ready code patches. This step consumes one credit. Scans that produce no findings are always free.


Authentication & Credits

ose signup          # create a free account
ose login           # log in (saves API key to ~/.ose/config.json)
ose whoami          # confirm your identity and credit balance
ose logout          # remove locally saved credentials
ose buy             # interactive credit pack purchase

For CI/CD, skip the login flow:

export OSE_API_KEY=ose_sk_your_key_here
ose audit ./project

Credit Tiers

Tier Credits Resets
Free 5 Every 7 days
Starter 50 Never expire
Pro Hacker 300 Never expire
Enterprise 1500 Never expire

Audits with no findings do not consume credits.


Installation Options

Method Command Notes
pipx pipx install ose-auditor Recommended — isolated env
npm global npm install -g ose-auditor Good for Node-first teams
npx npx ose-auditor audit . Zero install, auto-installs on first run
pip pip install ose-auditor Use inside a venv

Requires Python 3.9+ and a Node.js/TypeScript project to audit.


Exit Codes

Code Meaning
0 Success (including no findings)
1 General error (bad path, auth failure, network)
2 Audit ran but the server reported a failure

License

MIT — client layer, parser, MCP server, and contracts. The FSA detection core (ose-auditor-fsa) is proprietary and distributed as compiled wheels only.

Release files for ose-auditor 1.1.9

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ose-auditor 1.1.9
File Size Uploaded
ose_auditor-1.1.9.tar.gz 55.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ose-auditor 1.1.9
File Interpreter ABI Platform
ose_auditor-1.1.9-py3-none-any.whl Python 3 none any Details

Total release size: 111.9 kB

Release files / ose_auditor-1.1.9.tar.gz

Download URL ose_auditor-1.1.9.tar.gz
Size 55.6 kB
Tags Source
SHA-256 checksum
How to use checksums
d6ed66a44ff53d5c6f10038405ffb46f217179376998f02d17555cef4841bb42
BLAKE2b-256 checksum
How to use checksums
40574f208aae6a9b7fd933492bf8f9a614a7abd278af3ef3c486ad675a1cbcd6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.0

Release files / ose_auditor-1.1.9-py3-none-any.whl

Download URL ose_auditor-1.1.9-py3-none-any.whl
Size 56.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
acb0498a313ae08c71652bd18f49a10e709c71b234ad0db7fe79aad312d078b5
BLAKE2b-256 checksum
How to use checksums
31c166e4d334cef2d34ee92701967dfdf865f970b704a3d058b321de07586a52
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.0

Release history Release notifications | RSS feed

This release

1.1.9 This release

2 release files

1.1.8

2 release files

1.1.7

2 release files

1.1.6

2 release files

1.1.5

2 release files

1.1.4

2 release files

1.1.3

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page