Interesting thought. I would assume some audits have been done via blackbox testing of some sort (e.g. hardware monitor, routing all traffic through a proxy and logging it, etc.) by some infosec group/Co, but I also haven’t researched that.
I think there was a talk on breaking LittleSnitch at either Defcon or B-sides a few years back. I couldn't get in though; it was full. Whatever it was is probably fixed by now anyway.