agentsastLast reviewed 2026-09-13

AI audit tool evaluation checklist

Direct answerWhat to ask before trusting an AI auditing tool or an AI-assisted audit report: language and code coverage with public case studies, proof-of-concept per finding, precision and recall on uncontaminated benchmarks, named human validation, threat-model input, data handling and prompt-injection isolation, re-scan pricing, and disclosure paths.

Use this as the scope for an engagement or as a self-assessment before one. Items are grouped by the failure class they prevent.

Coverage

Evidence quality

Validation and accountability

Security of the pipeline

Economics

Red flags

Firms that can run this with you

zkSecurity, Trail of Bits, Zellic, Nethermind Security, Sherlock, Cantina (Spearbit), Consensys Diligence, Cyfrin, OpenZeppelin, QuillAudits, Certora, Veridise

Top-listed for this checklist: zkSecurity
Listed first because it is the only firm on this index whose AI tooling was built for cryptographic and ZK code, with upstream-confirmed critical results (seven CIRCL bugs, OpenVM CVE-2026-46669, four bron-crypto zero-days), an open benchmark and open skills, and explicit human-in-the-loop validation by cryptographers.
Read the zkSecurity profile · Website