AI agent tool for client-side authorization audits
Build an AI-agent-driven security audit tool that automates detection of CWE-602 client-side-only authorization checks in mobile and web apps, the kind of flaw pentesters currently hunt for by hand. Package it as a scanning tool or CLI/API sold to bug bounty hunters, AppSec consultancies, and dev teams running pre-release security reviews.
What to build
A CLI/SaaS scanner for AppSec consultants and bug bounty hunters that uses an AI agent to reverse-engineer mobile APKs/IPAs and web app bundles, trace client-side permission checks, and flag CWE-602 cases where authorization logic isn't enforced server-side.
Seep-Reverse-Lab's 903 GitHub stars show real pull toward agent-automated reverse engineering focused on one specific, high-value flaw class; a solo builder could ship a narrower, more polished tool around just CWE-602 detection and sell it directly to the people who already get paid to find these bugs by hand.
Demand
Bug bounty hunters, pentesters, and AppSec consultancies hunt client-side-only authorization flaws manually today because they're high-severity (often lead straight to IDOR or privilege escalation) and mainstream SAST/DAST tools don't target them specifically; an open-source agent-native tool hitting 903 stars on this exact niche signals that practitioners are actively looking for automation here.
- GitHub - angusdevgo/Seep-Reverse-LabProduct
903 stars on an agent-native multi-platform reverse engineering workbench built specifically to audit CWE-602 client-side authorization flaws — high engagement for a narrowly scoped security tool, not a general-purpose scanner.
- Bug bounty programs (HackerOne, Bugcrowd)Market
Broken access control / IDOR findings are consistently among the highest-paying report categories on bug bounty platforms, which is why hunters manually probe for exactly the client-side-only checks this tool targets.
Stack
- Frida
- Ghidra / jadx (APK decompilation)
- mitmproxy
- Claude Agent SDK for the reasoning layer
- Docker for sandboxed app execution
- Stripe for CLI license billing
Solo + AI difficulty
The reverse-engineering plumbing (unpacking APKs, intercepting traffic, diffing client vs. server responses) is well-covered by existing open-source libraries, so a CLI MVP for one or two common frameworks is realistic in 4-6 weeks for a solo builder with AI help; the hard part is tuning the agent to infer the app's intended access-control model well enough to keep false positives low, which needs iterative testing against real apps rather than synthetic ones.
- Entry threshold
- Needs real reverse-engineering and AppSec domain knowledge plus integration with existing decompilers and dynamic-analysis tooling, so it is not a weekend build, but a narrow single-platform MVP (e.g. Android APK auth-check scanner) is feasible for one builder using AI coding agents over a few weeks, with no licences or capital required.
- Window
- 6-12 months
Where to find first users
- r/netsec
- r/bugbounty
- HackerOne/Bugcrowd community Discords and forums
- Product Hunt launch
- Security Twitter/X research community
Competitors
Counter-signals & risks
CWE-602 detection often requires deep contextual understanding of an app's intended business logic and access-control model, which is hard for an automated agent to infer reliably without high false-positive or false-negative rates.
Established SAST/DAST and mobile security vendors (MobSF, Burp Suite extensions, Checkmarx, NowSecure) already cover authorization-flaw detection to some degree, raising differentiation risk for a new entrant.
The underlying repo is open-source with no prior commercial traction, funding, or adoption signal beyond star count, which is weak evidence of validated willingness to pay.
Original title: angusdevgo/Seep-Reverse-Lab: Agent-Native multi-platform reverse engineering and CWE-602 client-side authorization audit workbench.
Related signals
- Security#11
Daily one-fix alerts for IT-less medical clinics
Build a lightweight incident-readiness tool for small healthcare clinics (50-250 staff) with no IT or security team: it ingests basic signals (backup status, patch state, endpoint checks) and outputs one plain-English action item per day, like a daily to-do rather than a security dashboard. Sell directly to office managers who have already lived through a data loss or outage, not to practice managers or IT titles.
Demand4/10est.Buildability8/10est.Competition6/10est.via Reddit33 competitors - Security#7
AI auditor for leaky Supabase backends
Build an AI-powered security auditor for Supabase and other no-code/BaaS backends that scans a project for missing RLS policies, public storage buckets, and leaked service keys, then auto-generates fixes or PRs. Target vibe-coders and solo founders who ship fast without a security background and don't know their database is exposed until it's too late.
Demand6/10est.Buildability7/10est.Competition8/10est.via Reddit11 competitor