Doramagic.ai Chinese

Security Review & Permission Governance · Public

vorim-agent-audit

Free AI agent code hygiene checker. Scans for hardcoded LLM keys, shared credentials, and long-lived permissions in TypeScript, JavaScript, and Python projects. By Vorim AI.

Last verification date: 2026-07-27 Verification method: source evidence, semantic profile, public page gate, and static build acceptance.

Publication status · 2026-07-27

What is vorim-agent-audit?

01

Quick decision

Use this section to decide whether the project is worth a deeper read.
Best forUsers who want source-backed project understanding before installing it.

Match the project to your task before installing it.

Capabilityskill, recipe, host_instruction, eval, preflight

Free AI agent code hygiene checker. Scans for hardcoded LLM keys, shared credentials, and long-lived permissions in TypeScript, JavaScript, and Python projects. By Vorim AI.

RepositoryVorim-AI-Labs/vorim-agent-audit

1 stars · 0 forks

02

What it can do

Translate the upstream project into concrete capabilities the user can judge before installing.
1

Introduction and Installation

Related topics: Architecture and Scanning Pipeline, CLI Options, Output, and CI Integration

Source: https://github.com/Vorim-AI-Labs/vorim-agent-audit / Human Manual
2

Architecture and Scanning Pipeline

Related topics: Detection Rules and Pattern Catalogue, CLI Options, Output, and CI Integration

Source: https://github.com/Vorim-AI-Labs/vorim-agent-audit / Human Manual
3

Detection Rules and Pattern Catalogue

Related topics: Architecture and Scanning Pipeline, CLI Options, Output, and CI Integration

Source: https://github.com/Vorim-AI-Labs/vorim-agent-audit / Human Manual
4

CLI Options, Output, and CI Integration

Related topics: Introduction and Installation, Architecture and Scanning Pipeline

Source: https://github.com/Vorim-AI-Labs/vorim-agent-audit / Human Manual
5

Doramagic Pitfall Log

Source-linked risks stay visible on the manual page so the preview does not read like a recommendation.

Source: Doramagic discovery, validation, and Project Pack records

Sources: https://github.com/Vorim-AI-Labs/vorim-agent-audit, Human Manual, Project Pack evidence, and downstream validation signals.

03

Community Discussion Evidence

Project-level external discussion stays visible on the detail page, not only inside the manual.
Stars1 stars
Forks0 forks
Contributors2 contributors
Licenseunknown

Community Discussion Evidence

2 source-linked items

Review these external discussions before using vorim-agent-audit with real data or production workflows. They are review inputs, not standalone proof that the project is production-ready.

04

How to start

Only source-backed commands are shown here. Verify them in an isolated environment first.
1

Try the prompt first

Test the workflow without installing the upstream project.

preview
2

Read the Human Manual

Understand inputs, outputs, limits, and failure modes.

manual
3

Take context to your AI host

Use the compiled assets in your preferred AI environment.

context
4

Run sandbox verification

Confirm install commands and rollback before using a primary environment.

verify
npx @vorim/agent-audit

Official start command · https://github.com/Vorim-AI-Labs/vorim-agent-audit#readme · verified: yes

05

Human Manual

The English page must expose the real manual, not a short placeholder.

8+ sections · Human Manual

vorim-agent-audit Manual

The detection layer is organised as a thin dispatcher around a shared pattern registry. Patterns (regexes, string templates, and helper matchers) live in src/patterns.ts so that several ru...

Open the full manual
  1. https://github.com/Vorim-AI-Labs/vorim-agent-audit Project Manual
  2. Table of Contents
  3. Introduction and Installation
  4. Related Pages
  5. What Is vorim-agent-audit
  6. Scope of Checks
  7. Installation
  8. First Run and Workflow
1

Introduction and Installation

Related topics: Architecture and Scanning Pipeline, CLI Options, Output, and CI Integration

Source: https://github.com/Vorim-AI-Labs/vorim-agent-audit / Human Manual
2

Architecture and Scanning Pipeline

Related topics: Detection Rules and Pattern Catalogue, CLI Options, Output, and CI Integration

Source: https://github.com/Vorim-AI-Labs/vorim-agent-audit / Human Manual
3

Detection Rules and Pattern Catalogue

Related topics: Architecture and Scanning Pipeline, CLI Options, Output, and CI Integration

Source: https://github.com/Vorim-AI-Labs/vorim-agent-audit / Human Manual
4

CLI Options, Output, and CI Integration

Related topics: Introduction and Installation, Architecture and Scanning Pipeline

Source: https://github.com/Vorim-AI-Labs/vorim-agent-audit / Human Manual
5

Doramagic Pitfall Log

Source-linked risks stay visible on the manual page so the preview does not read like a recommendation.

Source: Doramagic discovery, validation, and Project Pack records

06

AI Context Pack and portable assets

After deciding to continue, take the project context into your own AI host.

Complete pack plus user-owned assets

These files are planning and verification assets for Claude Code, Codex, Gemini, Cursor, ChatGPT, and other AI hosts.

07

Preflight checks

Treat this page as a planning asset, not proof that your local environment is ready.

08

Pitfall Log and verification risks

Doramagic surfaces high-risk items before users treat a candidate capability as verified.
medium

Identity risk requires verification

May increase setup, validation, or first-run risk for the user.

medium

Capability evidence risk requires verification

May increase setup, validation, or first-run risk for the user.

medium

Maintenance risk requires verification

May increase setup, validation, or first-run risk for the user.

medium

Security or permission risk requires verification

May increase setup, validation, or first-run risk for the user.

medium

Security or permission risk requires verification

May increase setup, validation, or first-run risk for the user.

low

Maintenance risk requires verification

May increase setup, validation, or first-run risk for the user.

low

Maintenance risk requires verification

May increase setup, validation, or first-run risk for the user.