We build audit skills for AI coding agents — deterministic static analysers paired with a forced-analysis protocol, so a finding always comes with the exact interleaving or failure path that proves it.
The method. A scanner enumerates candidate sites by AST analysis: same input, same candidates, every run. Then the agent has to demonstrate the concrete failure — which actors, in which order, and what the caller observes. If it cannot construct that, the candidate is dismissed with the reason instead of padding the report.
What we publish. Every benchmark number is labelled as automated, independently verified, or agent-assisted review. Figures we cannot confirm are published as lower bounds, and the classification data behind them ships so the judgement can be disputed.
- cpython-concurrency-audit — we scanned all 593 files of the CPython 3.14.6 standard library and classified every candidate the scanner produced: 18 actionable hazards, 37 false positives, and what the false positives taught us about our own rules.
Built for Claude Code, Cursor, Codex CLI and anything else that reads SKILL.md. Python 3.9+,
standard library only, no network, no telemetry, read-only on your code.
- Interleavo — concurrency and idempotency: lost updates, TOCTOU races, duplicate webhook effects, double charges, unsafe locks.
- Scopewall — multi-tenant isolation: it infers your tenancy model first, then audits every query against it, and refuses loudly when no model can be inferred.
- Unwindo — failure paths: swallowed writes, silent fallbacks, retry storms, missing timeouts, unbounded fan-out.
All three at mavilinklabs.gumroad.com — one-time purchase, 14-day refund, no licence key or activation.
Built by MAVİLİNK FİBER TELEKOMÜNİKASYON HİZMETLERİ SANAYİ TİCARET LİMİTED ŞİRKETİ, a telecom and software company in Türkiye · info@mavilinkfiber.com.tr