Getting started with Hi AUDIT
Start with your Hi AUDIT account. The installation guide in your account is the source for the setup steps available to you.
Installation
Create an account or sign in
Use the normal signup or login page on app.hiaudit.io. If signup is closed, follow the availability message shown there.
Open Projects
After signing in, open Projects to manage your workspace. Confirm that you are using the intended account before installing.
Open your account's installation guide
Sign-in required
Open the installation tab in your account and follow the instructions for your operating system and editor. Use the commands and configuration shown there.
Check the connection in your editor
Follow the editor steps in the guide. Check its MCP settings and any connection errors before starting work with your own repository.
Guides are available in English and Japanese.
Quick start
Once the connection is confirmed, choose a small repository you are authorized to review. State the scope and ask your assistant to explain the findings and their evidence.
Review each finding against your code and record confirmed issues, false positives, and questions for a human reviewer. Recheck the changed code after a fix.
Read the findings guideMCP tools
15 tools are exposed to your IDE. Six cover web codebases, and nine cover smart contracts.
Web
| web2_analyze | Static analysis for TS/JS, Python, Go, Rust, Java+ |
| web2_finding_details | Full context for a specific web2 finding |
| web2_detectors | List web2 detectors and rule categories |
| web2_taint | Track untrusted data from source to sink |
| web2_security | OWASP Top 10 posture scoring with CWE mapping |
| web2_errors | Error-handling and information-leak analysis |
Smart contracts
| analyze | Run static analysis across a Solidity codebase |
| finding_details | Full context and traces for a specific finding |
| detectors | List available detectors and their severity classes |
| related_functions | Functions reachable from a target function |
| contract_summary | High-level summary of a contract's behavior |
| storage_layout | Storage slot layout and upgrade-safety checks |
| access_control | Role and permission mapping across contracts |
| inheritance_graph | Contract inheritance and dependency graph |
| gas_report | Gas usage hotspots and optimization candidates |
Playbooks
23 skill playbooks encode senior-auditor workflows. Trigger them by name in chat, e.g. hiauditagent poc or hiauditagent web2 owasp.
Web
Smart contracts
Solana
Supported languages
Web analysis and taint tracking cover the major application languages, including legacy COBOL codebases. Smart-contract analysis covers Solidity and Solana (Anchor) programs.
Security & data handling
Before sending source code, ask your account owner or the Hi AUDIT team to confirm the data-handling terms that apply to your use.
- Which files and credentials are sent, and who can access them?
- Where are source files, findings, and reports stored, and for how long?
- How do deletion requests work, including backups?
- Is submitted content used for model training, and which providers process it?
