TRAP v2.0.0 — True Readiness Audit Prompt
First public release of TRAP — the True Readiness Audit Prompt.
An adversarial, evidence-first production-readiness audit you paste into any AI coding assistant with repo access. It refuses to fake an audit (Rule 0) and refuses to call anything secure without citing the code that proves it.
Highlights
- Rule 0 — Access Gate: won't audit code it can't actually read.
- Three-verdict evidence standard: ✅ VERIFIED / ❌ NOT PRESENT / ❓ UNKNOWN — where not present is a finding, never a pass.
- Asserted ≠ Verified: a declared-but-untested access control is reported as NOT PRESENT.
- 11 phases: system model → threat model → security review → privacy → failure testing → attack mode → performance → code quality → out-of-repo controls → release checklist → automated cross-check.
- Mandatory Self-Challenge + iterative Remediation Loop.
What's in the repo
TRAP.md— the canonical prompt, ready to copy-paste.docs/EXAMPLE-AUDIT.md— a full illustrative audit so you can see the output before running it.- Versioned snapshot, changelog, contributing guide, MIT license.
See the CHANGELOG for the full list.
☕ Find it useful? https://www.buymeacoffee.com/bikra