Docs

Getting started with Hi AUDIT

Start with your Hi AUDIT account. The installation guide in your account is the source for the setup steps available to you.

Installation

  1. Create an account or sign in

    Use the normal signup or login page on app.hiaudit.io. If signup is closed, follow the availability message shown there.

  2. Open Projects

    After signing in, open Projects to manage your workspace. Confirm that you are using the intended account before installing.

  3. Open your account's installation guide

    Sign-in required

    Open the installation tab in your account and follow the instructions for your operating system and editor. Use the commands and configuration shown there.

  4. Check the connection in your editor

    Follow the editor steps in the guide. Check its MCP settings and any connection errors before starting work with your own repository.

Read the setup guide

Guides are available in English and Japanese.

Quick start

Once the connection is confirmed, choose a small repository you are authorized to review. State the scope and ask your assistant to explain the findings and their evidence.

Review each finding against your code and record confirmed issues, false positives, and questions for a human reviewer. Recheck the changed code after a fix.

Read the findings guide

MCP tools

15 tools are exposed to your IDE. Six cover web codebases, and nine cover smart contracts.

Web

web2_analyzeStatic analysis for TS/JS, Python, Go, Rust, Java+
web2_finding_detailsFull context for a specific web2 finding
web2_detectorsList web2 detectors and rule categories
web2_taintTrack untrusted data from source to sink
web2_securityOWASP Top 10 posture scoring with CWE mapping
web2_errorsError-handling and information-leak analysis

Smart contracts

analyzeRun static analysis across a Solidity codebase
finding_detailsFull context and traces for a specific finding
detectorsList available detectors and their severity classes
related_functionsFunctions reachable from a target function
contract_summaryHigh-level summary of a contract's behavior
storage_layoutStorage slot layout and upgrade-safety checks
access_controlRole and permission mapping across contracts
inheritance_graphContract inheritance and dependency graph
gas_reportGas usage hotspots and optimization candidates

Playbooks

23 skill playbooks encode senior-auditor workflows. Trigger them by name in chat, e.g. hiauditagent poc or hiauditagent web2 owasp.

Web

web2-overviewweb2-analyzerweb2-taintweb2-owaspweb2-filterweb2-reportweb2-cobol

Smart contracts

overviewanalyzerarchitectureaccessstoragegasdiffexplainersimplifyfiltervalidatepocfixreport

Solana

solana-overviewsolana-access

Supported languages

TypeScriptJavaScriptPythonGoRustJavaKotlinC#RubyPHPCOBOLSolidityRust (Solana / Anchor)+ more

Web analysis and taint tracking cover the major application languages, including legacy COBOL codebases. Smart-contract analysis covers Solidity and Solana (Anchor) programs.

Security & data handling

Before sending source code, ask your account owner or the Hi AUDIT team to confirm the data-handling terms that apply to your use.

  • Which files and credentials are sent, and who can access them?
  • Where are source files, findings, and reports stored, and for how long?
  • How do deletion requests work, including backups?
  • Is submitted content used for model training, and which providers process it?
Contact the team about setup or data handling