Python Security Audit & Report
Budget: £20 – £250 GBP
I will hand you a Python code-base that already runs inside a Kali Linux environment. Your sole focus is to uncover and remediate security vulnerabilities. To do that, please rely on the exact tool-set I use internally—Bandit for static checks, Pytest for security-oriented unit tests, and OWASP ZAP for dynamic assessment of any exposed endpoints. Performance or feature refactoring is out of scope; I only care about hardening the code.
After the fixes, I need a formal report (2300–2500 words, academic tone) that captures:
• the initial risk profile revealed by Bandit, ZAP and targeted Pytest failures
• a clear walk-through of each exploit or weakness you reproduced, including proof-of-concept snippets or ZAP evidence
• the remediation steps you applied, referencing the exact code sections you patched
• a short verification section showing the clean Bandit score, passing Pytests and ZAP re-scan results
• any residual risk and recommendations for future hardening
Please embed terminal output, command flags and code excerpts where helpful, but keep the prose narrative fluent—think of something suitable for a technical appendix of a security audit.
Deliverables
1. Patched Python source files (Git diff or full replacement).
2. The 2 300–2 500 word report in PDF or Markdown.
3. Raw tool logs (Bandit JSON, Pytest XML/HTML, ZAP session) in an archive.
I’m happy to clarify the preferred structure or citation style before you begin.
After the fixes, I need a formal report (2300–2500 words, academic tone) that captures:
• the initial risk profile revealed by Bandit, ZAP and targeted Pytest failures
• a clear walk-through of each exploit or weakness you reproduced, including proof-of-concept snippets or ZAP evidence
• the remediation steps you applied, referencing the exact code sections you patched
• a short verification section showing the clean Bandit score, passing Pytests and ZAP re-scan results
• any residual risk and recommendations for future hardening
Please embed terminal output, command flags and code excerpts where helpful, but keep the prose narrative fluent—think of something suitable for a technical appendix of a security audit.
Deliverables
1. Patched Python source files (Git diff or full replacement).
2. The 2 300–2 500 word report in PDF or Markdown.
3. Raw tool logs (Bandit JSON, Pytest XML/HTML, ZAP session) in an archive.
I’m happy to clarify the preferred structure or citation style before you begin.