Audit AI-generated code changes for risk before you commit them.
CodeAuditor AI is a hackathon project that sits between your AI coding assistant and your Git commit. It analyses a proposed diff and surfaces three categories of risk so developers can make an informed decision before merging.
| Agent | Responsibility |
|---|---|
| Requirement Agent | Checks whether the change actually fulfils the stated requirement or ticket description |
| Security Agent | Scans for common vulnerabilities — hardcoded secrets, injection risks, insecure defaults |
| Impact Agent | Identifies blast radius — which files, functions, or services are affected |
| Coordinator | Aggregates the three agent reports into a single risk score and summary |
CodeAuditorAI/
├── backend/
│ ├── app.py # Flask entry point
│ ├── requirements.txt # Python dependencies
│ ├── coordinator/ # Aggregates agent results → final report
│ ├── requirement_agent/ # Requirement-coverage analysis
│ ├── security_agent/ # Security vulnerability scan
│ └── impact_agent/ # Change impact analysis
├── frontend/ # (UI — TBD)
├── sample_code/ # Example diffs for demo / testing
└── bob_sessions/ # Saved Bob AI session logs
- Python 3.10+
- pip
cd backend
pip install -r requirements.txt
python app.pyThe API will be available at http://localhost:5000.
| Method | Path | Description |
|---|---|---|
GET |
/health |
Health check |
POST |
/audit |
Submit a diff for full audit |
Example request:
curl -X POST http://localhost:5000/audit \
-H "Content-Type: application/json" \
-d '{"diff": "--- a/app.py\n+++ b/app.py\n@@ -1 +1 @@\n+import os\n+password = \"hunter2\"", "requirement": "Add env-var support"}'Example response:
{
"risk_score": 8,
"summary": "Hardcoded password detected. Requirement partially met.",
"agents": {
"requirement": { "met": false, "notes": "Requirement calls for env-var; change uses a literal." },
"security": { "issues": ["Hardcoded credential on line 2"] },
"impact": { "files_changed": ["app.py"], "risk": "low" }
}
}- Never commit
.envor credentials — see SECURITY.MD - All API keys must go in a
.envfile (already git-ignored)
- Backend: Python, Flask
- AI / LLM: IBM watsonx (planned)
- Frontend: TBD (plain HTML or React)
Built for the IBM Hackathon. Contributors: Dhyan K N