Skip to content
Ubaid_ur_Rehman
All work

shadowaudit

Active development

CLI that turns undocumented API routes into reviewable security context, with SARIF output your CI already understands.

Problem

The bug class that keeps recurring is an endpoint that exists in code but not in the spec, not in the tests, and not in the WAF ruleset. Route inventory is derivable from framework source, but almost nobody derives it.

What I built

Parses framework source to enumerate routes, diffs that against a supplied OpenAPI specification, and emits a report with authentication context and OWASP API mapping. Output is SARIF, so it drops into an existing CI pipeline as a step rather than a new dashboard.

Impact

Turns route inventory into a reviewable artefact. Finds classes of endpoint exposure that spec review misses, and fails a build instead of producing a warning nobody reads.

Highlights

  • Static analysis engine with multi-framework scanner support
  • OWASP API Top 10 risk mapping with severity scoring
  • Published on npm with active community usage
  • GitHub Action integration for CI/CD pipelines
  • Live dashboard at shadowaudit-dashboard.vercel.app

Stack

  • Node.js
  • Security
  • Static Analysis
  • OWASP
  • CLI
LiveGitHub