Auditing the auditor with four AI agents

Discover how four AI agents audited turva.dev: 91 findings, false positives, and lessons for real audits.

sábado, 4 de julio de 2026 • 2 min read • Q2BSTUDIO Team

The true audit: reading every line of code

System and code auditing is an essential practice in software development, especially when using AI agents to automate critical processes. A recent case has drawn attention in the sector: an auditing firm decided to apply its own methods to its digital infrastructure, using four artificial intelligence agents to examine every line of its platform. The goal was to demonstrate that an automated scanner cannot replace deep human analysis, but also that well-configured agents can uncover deviations that go unnoticed by traditional tools.

The process, which involved analyzing approximately 5,400 lines of source code, MCP server configuration, and README files from public repositories, yielded 91 findings. Most were minor drifts typical of any evolving code: discrepancies between advertised algorithms and those actually implemented, poorly expanded protocol names, tables that never rendered correctly, or errors in the wording of legal pages. However, the most revealing aspect were the false positives. Four alerts classified as critical turned out to be incorrect after manual verification. One claim about the deployed version was actually a caching issue; another about a scanner's rating was based on a misinterpretation of scoring scales.

These incidents demonstrate that artificial intelligence applied to auditing requires a layer of human validation to avoid correcting what is already correct. In the business world, where cybersecurity and precision are critical, having tools that automate initial detection but allow for expert review is essential. This is where companies like Q2BSTUDIO add value, integrating AI agents into custom application workflows to optimize software quality without sacrificing control.

The finding that did hold up was the most significant: a documented promise that a service did not log data contradicted the actual configuration, which had observability enabled. Correcting that mismatch involved changing reality to align with the documentation, not the other way around. This is the essence of an honest audit: verifying every claim against the primary source. In a context where companies adopt AWS and Azure cloud services and business intelligence platforms like Power BI, consistency between what is said and what is implemented is critical for customer trust.

From the perspective of custom software development, this case underscores the need to integrate continuous verification processes. AI agents can examine thousands of lines in seconds, but they require clear rules to interpret information. For example, a cache returning an old version can generate a false alert; a scanner that assigns scores in levels can be misinterpreted as percentages. Q2BSTUDIO's experience in business intelligence and AI services for companies allows for designing systems that minimize such noise, combining automation with expert oversight.

If your organization is considering implementing AI agents to audit your infrastructure or develop custom applications requiring high quality standards, we invite you to explore how our cybersecurity services can integrate with automated verification workflows. The main lesson from this exercise is that a finding is not valid until it is verified against the source, and that the combination of artificial intelligence and human judgment remains the most robust formula for ensuring software integrity.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.