Inventory
Read source files as text, detect frameworks, package managers, config files, and project shape.
A-DAP-T performs a static, evidence-led review of project files to map release risk, weak controls, policy blockers, and fix-first actions before deployment.
The scanner turns project evidence into a release decision. Each step creates an artifact used by the report workspace.
Read source files as text, detect frameworks, package managers, config files, and project shape.
Build dependency, API, AppSec, context, capability, and trust-boundary artifacts.
Look for visible auth, rate limits, approval gates, audit logs, allowlists, masking, and isolation.
Combine score, hard blockers, and required controls into BLOCK, REVIEW, or ALLOW.
Turn evidence into a fix-first sequence with expected gate impact and validation steps.
Package hygiene and supply-chain drift.
Missing lockfile · unpinned spec · direct git dependencyRoutes and endpoint controls.
Auth · rate limit · CORS · upload boundaryRisky static code paths.
SSRF · path traversal · command sink · unsafe extractionWhat the app can actually do.
Tool action · external effect · sensitive dataWhether risky behavior is protected.
Approval · audit · allowlist · masking · isolationWhether the release can move forward.
Decision · blockers · fix sequence · validationA-DAP-T produces a security score, but release status also depends on required controls and hard blockers. A high score can still need review if a critical guardrail is missing.
A-DAP-T reads project files and configuration. It does not execute uploaded projects or confirm live exploits.
Some controls may live outside the scanned repository. The report says what was visible in the submitted project.
The assistant helps interpret report evidence. It does not invent the verdict or replace manual security review.
Start with the built-in demo, then scan your own GitHub repository or ZIP project.