Keyoxide doesn't use any cryptography, everything is handled by identities in PGP. I doubt it needs any auditing.
The only reasonable attack vector I can see is hijacking the website (or proxy server) to return different keys or show something is verified when it's actually not.