OSE Auditor
OSE Auditor is an autonomous financial and logic exploit detection engine for Node.js and TypeScript backends. It uses deterministic code analysis combined with AI-powered remediation to surface money-losing vulnerabilities before they reach production.
It catches what generic AI models and traditional SAST tools miss: broken authorization gates on financial mutations, double-spend race conditions, unchecked external payment calls, privilege escalation via user-controlled roles, invalid order lifecycle transitions, and more.
Why OSE Auditor?
Most SAST tools find injection and XSS. OSE Auditor finds the bugs that drain your users' money:
- A payment route that processes charges without verifying the caller is authenticated
- A withdrawal endpoint where two concurrent requests can both read the same pre-deducted balance
- A Stripe call whose result is never checked before balance is decremented
- An order marked
completedbefore payment has confirmed - A role check that reads
req.body.role— set by the attacker
These bugs are invisible to linters, missed by code review, and never caught in unit tests because they require reasoning about ordering, ownership, and financial semantics across an entire function's control flow.
Quick Start
# Install (pipx recommended — isolated, no PEP 668 conflicts)
pipx install ose-auditor
# Create a free account
ose signup
# Audit your project
ose audit ./your-nodejs-project
# Buy more credits when you need them
ose buy
Or with npm/npx — zero Python setup required:
npm install -g ose-auditor
ose audit ./your-nodejs-project
# or without installing
npx ose-auditor audit ./your-nodejs-project
How It Works
OSE Auditor runs a three-stage pipeline entirely on your machine before any data leaves:
-
Parser — walks your project, strips comments, computes hashes, assembles a normalized source index (Contract A). Open-source, stdlib-only, no network I/O.
-
Financial Semantic Analyzer (FSA) — parses every JavaScript/TypeScript file into an AST using tree-sitter, builds a per-function state transition graph (validation nodes, external-call nodes, state-mutation nodes, in source order), then applies deterministic vulnerability signatures. No AI, no false-positive lottery — rules are hardcoded and auditable. The FSA core is compiled and proprietary; the client layer that calls it is MIT-licensed.
-
Patch Generation (OSE Server) — if the FSA finds vulnerabilities, the manifest is sent to the OSE Server, which calls a configurable LLM (Claude, GPT-4, or Groq) with track-specific few-shot prompts to generate production-ready code patches. This step consumes one credit. Scans that produce no findings are always free.
Authentication & Credits
ose signup # create a free account
ose login # log in (saves API key to ~/.ose/config.json)
ose whoami # confirm your identity and credit balance
ose logout # remove locally saved credentials
ose buy # interactive credit pack purchase
For CI/CD, skip the login flow:
export OSE_API_KEY=ose_sk_your_key_here
ose audit ./project
Credit Tiers
| Tier | Credits | Resets |
|---|---|---|
| Free | 5 | Every 7 days |
| Starter | 50 | Never expire |
| Pro Hacker | 300 | Never expire |
| Enterprise | 1500 | Never expire |
Audits with no findings do not consume credits.
Installation Options
| Method | Command | Notes |
|---|---|---|
| pipx | pipx install ose-auditor |
Recommended — isolated env |
| npm global | npm install -g ose-auditor |
Good for Node-first teams |
| npx | npx ose-auditor audit . |
Zero install, auto-installs on first run |
| pip | pip install ose-auditor |
Use inside a venv |
Requires Python 3.9+ and a Node.js/TypeScript project to audit.
Exit Codes
| Code | Meaning |
|---|---|
0 |
Success (including no findings) |
1 |
General error (bad path, auth failure, network) |
2 |
Audit ran but the server reported a failure |
License
MIT — client layer, parser, MCP server, and contracts.
The FSA detection core (ose-auditor-fsa) is proprietary and distributed as compiled wheels only.
Release files for ose-auditor 1.1.9
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ose_auditor-1.1.9.tar.gz | 55.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ose_auditor-1.1.9-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 111.9 kB
Release files / ose_auditor-1.1.9.tar.gz
| Download URL | ose_auditor-1.1.9.tar.gz |
|---|---|
| Size | 55.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d6ed66a44ff53d5c6f10038405ffb46f217179376998f02d17555cef4841bb42
|
|
BLAKE2b-256 checksum How to use checksums |
40574f208aae6a9b7fd933492bf8f9a614a7abd278af3ef3c486ad675a1cbcd6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.0
|
Release files / ose_auditor-1.1.9-py3-none-any.whl
| Download URL | ose_auditor-1.1.9-py3-none-any.whl |
|---|---|
| Size | 56.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
acb0498a313ae08c71652bd18f49a10e709c71b234ad0db7fe79aad312d078b5
|
|
BLAKE2b-256 checksum How to use checksums |
31c166e4d334cef2d34ee92701967dfdf865f970b704a3d058b321de07586a52
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.0
|