# zkao > Drive zkao security audits from code: the REST API, the zkao CLI, the TypeScript SDK, the GitHub Action, and the agent skill. zkao audits code repositories for security bugs, with a focus on cryptography and zero-knowledge circuits. A project API token drives one project: list repositories, launch and poll scans, triage findings, edit repository guidance, read credit usage, and publish results. Every page is also served as Markdown at its URL with `.md` appended. The agent skill is at https://docs.staging.zkao.io/skill.md and the OpenAPI spec at https://docs.staging.zkao.io/openapi/v1.yaml. These docs describe staging (https://staging.zkao.io) and the @zksecurity/zkao-cli@next release. Set ZKAO_URL=staging.zkao.io. ## Documentation Sets - [Abridged documentation](https://docs.staging.zkao.io/llms-small.txt): a compact version of the documentation for zkao, with non-essential content removed - [Complete documentation](https://docs.staging.zkao.io/llms-full.txt): the full documentation for zkao ## Notes - The complete documentation includes all content from the official documentation - The content is automatically generated from the same source as the official documentation