---
title: "Assuming an upstream audit covers your configuration"
description: "A modular framework's audit is treated as covering the deployed system, but the audit examined the upstream base while your security depends on which…"
type: "failure-mode"
url: "https://zkpick.com/frameworks/failure-modes/assuming-an-upstream-audit-covers-your-configuration/"
section: "02 Choosing a framework"
authors:
  - "MarketComp"
publisher: "MarketComp"
version: "1.3"
updated: "2026-09-12"
license: "CC-BY-4.0"
json: "https://zkpick.com/data/frameworks/failure-modes/assuming-an-upstream-audit-covers-your-configuration.json"
---

*By MarketComp. Updated 2026-09-12. Version 1.3. CC BY 4.0.*

# Assuming an upstream audit covers your configuration

A modular framework's audit is treated as covering the deployed system, but the audit examined the upstream base while your security depends on which extensions you enabled and how they interact.

**Mitigation:** Establish what the upstream audit actually covered and treat your specific instantiation — the enabled extensions and their composition — as a separate review target.
