
RepoAuditor is a security-review pipeline for acquired codebases. It combines deterministic scanners, bounded architecture and trust-boundary analysis, human-reviewed findings, quantitative evidence summaries, and separate engineering and leadership reports.Evidence boundary: scanner matches and model outputs are review candidates, not proof of exploitability, actionability, compromise, exhaustive coverage, or production readiness. The package-local weak-RNG detectors are syntactic candidate detectors and do not execute PRNG recovery.
