Deadbolt's primary judge path is a keyless, evidence-backed Codex security audit. Its separate local API engine supports the hunt, patch, and re-analysis loop when configured.

A perfectly centered vertical flashlight beam illuminates a red security bug against a dark source-code graph.

PRIMARY PATH · NO API KEY

Run keyless in CodexAsk $deadbolt to audit source you own.
KEYLESS IN CODEXREAD-ONLY AUDITEVIDENCE BACKED
Run keyless in Codex

PRIMARY JUDGE PATH · CODEX SKILL

Run $deadbolt keylessly in Codex.

Install the Deadbolt Skill once, then audit the included InvoicePilot source without a separate API key.Read-only source reasoning audit · does not run the web engine or claim patch verification.
01INSTALL02ASK $deadbolt03AUDIT SAMPLE
RUN KEYLESS IN CODEX

THE MISSING SECURITY TEAM

Find the bug.Fix the risk.Re-analyze it.

Deadbolt gives solo builders the security loop enterprise teams already have: understand the application, find what matters, write the fix, and show whether the same hunt still finds it.

Run keyless in Codex See how the loop works

For repositories and deployments you own or are authorized to test.

The web product is the API-backed hunt → patch → re-analysis engine. The keyless $deadbolt Codex Skill is a separate read-only reasoning audit; it does not run this engine or claim patch verification.

BUILT FOR THE DEVELOPER WITHOUT

A SECURITY TEAMCODEQLCI/CDTIME TO BECOME AN EXPERT

ILLUSTRATIVE REMEDIATION FLOW · LOCAL API ENGINE

How the local engine is designed to work.Illustrative until a real run is recorded.

01

Add your source

Choose the application files you want Deadbolt to inspect.

02

Confirm authorization

Only audit code you own or are explicitly allowed to test.

03

Run the full loop

Use the API-backed engine to review evidence, focused patches, and affected-hunt re-analysis.

ILLUSTRATIVE REMEDIATION FLOWNOT A RECORDED RUN

ILLUSTRATIVE ACCESS CONTROL EXAMPLE

Example: one signed-in user can read another user's private record.

This example shows the evidence and before→after framing the local API-backed engine is designed to produce. It is not a claim that a live patch or verification run has been recorded.

BEFORE · EXAMPLE CROSS-TENANT READAFTER · EXAMPLE 404 DENIED
Run the keyless audit

THE CORE LOOP

A finding is not finished until the patched clone is re-analyzed.

Every result connects evidence, human impact, a focused patch, and a fresh run of the affected hunt lens.

01MAP

Threat-model the app

Trace entry points, identity, sensitive data, and trust boundaries before judging risk.

02HUNT

Reason across the code

Four focused passes hunt secrets, auth flaws, injection, and dangerous configuration.

03PATCH

Write the smallest fix

Turn every confirmed finding into a focused, reviewable diff with the human stakes attached.

04RECHECK

Re-analyze the patch

Run the affected hunt lens again against the patched clone and show whether the original root cause remains.

THE SAFETY BOUNDARY

Defend what you own. Never weaponize what you find.

Deadbolt reports evidence, plain-English impact, and patches. It does not probe third-party targets or produce turnkey attack tools.