Apex

AI security engineer for modern teams

The findings your team will actually fix.

Apex finds real, exploitable vulnerabilities in mission-critical code and hands your team fix-ready guidance — in a workspace built for validating and shipping fixes.

openclaw

OpenClaw audit

Validityinvalid19 of 19
CRITOPEN-8
Hook-triggered CLI cron runs receive owner MCP bearer tokens
AcceptedFix unverified
CRITOPEN-1
Trusted-proxy Control UI auth skips new-device pairing and accepts attacker-declared WS admin scopes
No fix review
CRITOPEN-2
Paired chat users can mint a setup code that silently auto-promotes a durable operator device
Pending MergeFix confirmed
CRITOPEN-3
Spoofed Control UI locality silently mints persistent admin device tokens
AcceptedFix not made
HIGHOPEN-15
Attacker-controlled skillKey lets one skill overwrite another skill's tools root
No fix review
HIGHOPEN-20
Bundle-MCP loopback bypasses its own exec denylist via sessions_spawn
No fix review
HIGHOPEN-11
Forged node exec lifecycle events bypass reduced-surface hardening and reach gateway host exec
No fix review
HIGHOPEN-19
Forwarded/UI exec approvals can blindly authorize hidden host commands because approval records store only truncated display text
No fix review
HIGHOPEN-16
Marketplace package installs can redirect runtime into unscanned hidden payloads via runtimeExtensions
No fix review
HIGHOPEN-13
Playwright act/select and fill paths bypass browser SSRF policy, then evaluate executes on the private page
No fix review
HIGHOPEN-10
Plugin install publishes executable code that the dangerous-code gate never scans
No fix review
HIGHOPEN-17
POSIX node system.run safe-bin auto-allow executes unquoted shell payload and leaks host secrets
No fix review
HIGHOPEN-9
Revoked node tokens can be self-restored from a pairing-only operator session
No fix review
HIGHOPEN-14
Setup-mode provider discovery auto-enables and executes untrusted workspace plugins
No fix review
HIGHOPEN-12
Shared-auth paired sessions bypass device ownership checks on pairing/token RPCs
No fix review
HIGHOPEN-18
Shell positional carriers let allowlisted find bypass strictInlineEval
No fix review
HIGHOPEN-6
First-time node connects expose system.run before node-pair admin approval
In reviewRunning62%
CRITOPEN-4
Same-host non-loopback trusted-proxy deployments let unprivileged local callers forge full operator HTTP identity
False positiveNo fix review
HIGHOPEN-7
Device-pair approval bypass exposes system.run before node.pair.approve
SkippedFix cancelled

Apex found bugs in

GitLab logoGitLabAnthropic logoAnthropicApple logoAppleCoinbase logoCoinbaseSentry logoSentrySupabase logoSupabaseSierra AI logoSierra AITikTok logoTikTokSuperhuman logoSuperhuman
01Finding detail

Every finding tells the full story.

Summary, affected code, impact assessment, and remediation steps in one view. No more switching between tools.

  • Impact context on every issue
  • PoC code with highlighted lines
  • Fix-ready recommendations
CriticalOPEN-3 · Spoofed Control UI locality mints admin device tokens

Summary

Same-LAN or shared-token caller can spoof Control UI locality, silently pair an admin device, and retain admin authority after shared-token rotation.

Recommendation

Verify the immediate peer before trusting proxy headers; derive scopes from stored paired device records.

Validated by security team· 2h ago

PoC · poc.mjs

const config = { gateway: { bind: "lan", auth: { mode: "token", token }, controlUi: { enabled: true, allowedOrigins: […], }, },};
02Collaboration
Discussion · OPEN-4

Maya K. · eng lead · 3h

Reproduced on staging — the forged headers get full operator scopes. Prioritizing for this sprint.

Jordan D. · security · 2h

Marking valid. Fix path in the finding covers peer verification.

Marked Valid
Share findings

Client-safe link

ai.cantina.xyz/share/8f3a…Copy

Passphrase

••••••••••
Create share link

One workflow for security and product.

Comment on findings in context, validate or dismiss as a team, and share client-safe views through passphrase-protected links.

  • Comment on findings
  • Validate to track progress
  • Share securely with clients
03Scans

Connect in minutes. Findings in a few hours.

Connect GitHub, pick repositories, and watch scans progress live — evaluated against real attacker behavior, not lint-like heuristics.

Scan #142 · openclaw @ mainRunning · 2h 08m
Analyzing auth boundaries…68%

Files

214

Lines

48,120

Findings so far

3

False positives

0

Proof, not promises

Trained on real audits, not synthetic data.

n01

50,000+

Real-world vulnerabilities analyzed

n02

9,000+

Expert security researchers contributing signal

n03

10+

Criticals and highs found in production code

n04

$25B+

In live funds secured

I was truly impressed by the subtle bugs that Cantina uncovered in an open-source cryptographic repository that I maintain, which had already gone through thorough reviews. Their AI-powered tool acts as a valuable safety net to catch bugs that humans and other tools may have missed.
Coinbase logo

Arash Afshar · Coinbase Cryptography Team

FAQ

Frequently asked questions

Apex uses AI-assisted code understanding to surface practical vulnerabilities, reduce false positives, and provide remediation guidance with context.

See your first findings today.

From a single scan to enterprise coverage, Apex shows what matters and helps your team fix it fast.