TotalApp Docs

Security Hub

Automated security auditing, dependency scanning, and AI-powered vulnerability analysis.

Overview

Security Hub is a purpose-built security auditing terminal. It combines automated scanning commands with AI-powered analysis to help you identify and remediate vulnerabilities in your codebase, dependencies, and infrastructure configuration.

The terminal uses two block types unique to security workflows: SelectBlock for interactive multi-option scope selection (narrow the audit to specific modules or check types), and RunBlock for multi-step audit sequences that show progress as each check completes.

Audit Commands

CommandWhat It Checks
security-analysis [path]Comprehensive static analysis of code at the specified path. Identifies injection risks, hardcoded credentials, unsafe dependencies, and misconfigurations.
scan-dependenciesChecks all declared dependencies (package.json, requirements.txt, etc.) against known vulnerability databases for CVEs.
check-secretsScans source files for accidentally committed secrets: API keys, tokens, passwords, private keys.
audit-permissionsChecks file and directory permissions for overly permissive settings that could allow privilege escalation.

Full Audit Mode

Running runFullAudit chains all available scan commands in sequence. This is the recommended starting point for a comprehensive security review.

  1. The terminal launches a RunBlock with steps for each scan command.
  2. Each step transitions from pending → running → done (or error) as the scan completes.
  3. After all scans finish, the terminal displays a summary of findings organised by severity.

Severity Categories

All findings are classified into four severity levels:

  • Critical — Must be fixed before deployment. Typically means exposed credentials or known exploitable CVEs with public PoCs.
  • High — Should be fixed in the current sprint. Significant attack surface or data exposure risk.
  • Medium — Schedule for the next sprint. Notable risk but requires specific conditions to exploit.
  • Low — Best practice improvements. Low exploitability but worth addressing over time.

AI Analysis

After each scan, the AI explains every finding in plain language and suggests concrete remediation steps. For each vulnerability, you receive:

  • Plain-language description — what the vulnerability is and why it matters.
  • Exploitability context — how an attacker would actually exploit it and what data or systems are at risk.
  • Remediation steps — specific code changes, configuration updates, or dependency upgrades needed to fix the issue.
  • Priority recommendation — based on severity and exploitability, the AI tells you which findings to tackle first.

Focus on Critical Findings First

When facing a long list of findings, start with Critical and High severities. These represent actual exploitable vulnerabilities. Medium and Low findings are real but pose less immediate risk — address them in maintenance cycles.

Report Export

After a full audit, click Export Report to download a timestamped security report. The report includes:

  • Audit timestamp and scanned path
  • Status, risk level, and issue count per protocol
  • Findings and summary per protocol

Reports are exported as JSON files (full-security-audit-<timestamp>.json) suitable for sharing with your team or including in a compliance review package.

SelectBlock Flows

Some audit commands use SelectBlock to let you interactively narrow the audit scope before scanning begins. For example, security-analysis on a large monorepo may first prompt you to select which sub-packages to include.

Interactive Prompts vs Full Scan

SelectBlock prompts are optional — pressing Enter without making a selection runs the full scan. Use scope selection when you want a faster focused scan during active development, and full scans for release audits or compliance checks.