Agents

41 agents, each with one job.

An agent is a specialist that checks one part of your app. One hunts for leaked keys, one reads your database rules, one follows the money through your checkout. The launch check sends only the ones your project needs.

Leaders

2 agents

  • launch-lead

    Maps a project before a launch check.

  • final-judge

    Takes the findings from all LaunchReadyKit checkers, removes duplicates and false alarms, runs the scoring script for the 0-100 launch score and verdict, and writes the launch report in plain language.

Security

10 agents · see the checks →

  • secrets-hunter

    Finds leaked API keys, passwords and tokens in source code, public environment variables, config files and build output.

  • git-history-scanner

    Searches a repository's git history for secrets and .env files that were committed in the past and can still be recovered, and checks whether the repository is public.

  • auth-checker

    Reviews login, signup, sessions and password reset to find ways someone could reach private data without logging in or get into an account that is not theirs.

  • rate-limit-checker

    Checks that login, signup and costly endpoints limit how often they can be called, so nobody can guess passwords at speed or run up the owner's bill on paid services such as AI models, email and SMS.

  • access-control-checker

    Works out who is allowed to do what in an app, then finds where someone can reach another user's or another team's data, give themselves more rights, or use an admin function.

  • upload-checker

    Checks that file uploads are limited by type and size, saved under safe names, and not readable by the wrong people.

  • injection-hunter

    Looks for places where user or AI-generated input can change a database query, run a command, read files, make the server fetch other addresses, or run scripts in other users' browsers.

  • headers-checker

    Checks the security headers a site sends, which other websites may call its API (CORS), protection against forged requests, and debug information leaking in production.

  • dependency-auditor

    Audits a project's packages for known security holes, fake or misspelled package names, missing lockfiles and outdated frameworks.

  • ai-abuse-checker

    Reviews how an app talks to AI models, to find ways a user could make the AI ignore its instructions, act on other users' data, leak what it was told, or be used at the owner's expense.

Database

6 agents · see the checks →

  • supabase-rules-checker

    Reviews a Supabase project's row-level security policies, views and database functions to find data that anyone on the internet can read or change.

  • supabase-storage-checker

    Reviews Supabase Storage buckets and their access policies to find private files that are public and files that any user can overwrite or delete.

  • firebase-rules-checker

    Reviews Firebase security rules for Firestore, Realtime Database and Storage, plus Admin SDK keys and Cloud Functions, to find data that anyone can read or change.

  • database-safety-checker

    Reviews how a project connects to its SQL database and whether the schema has the basic safeguards: a limited-rights user, encryption, connection pooling, indexes and constraints.

  • migration-checker

    Reviews how a project changes its database structure: whether migrations exist, whether a pending one would destroy data, whether seed scripts could reach production, and whether development and production share a database.

  • data-deletion-checker

    Checks whether users can delete their account and get a copy of their data, and whether deletion really removes their personal data from every table, from file storage and from outside services.

Database, production

3 agents · see the checks →

  • query-performance-checker

    Finds database queries that will slow down or fail as data and traffic grow: queries in loops, lists with no limit, filtering in app code, deep OFFSET paging, wildcard search and missing timeouts.

  • data-integrity-checker

    Finds places where data goes wrong when two requests arrive at once or a step fails halfway: balances and stock that lose updates, missing transactions, coupons used twice, unsafe retries, deleted rows that reappear and cascades that delete too much.

  • db-runtime-checker

    Finds database setup that breaks under real traffic and real deploys: pooler settings that crash queries, connection pools larger than the database allows, migrations that lock busy tables, raw database errors shown to users, no recovery from brief outages and stale replica reads.

Payments

2 agents · see the checks →

  • payments-checker

    Reviews checkout, subscriptions, pricing and refunds to find ways customers could pay the wrong amount, get the product without paying, or keep access after a refund.

  • webhook-checker

    Reviews payment webhook handlers for missing signature verification, duplicate processing, unhandled events and silent failures that lose paid orders.

Payments, production

2 agents · see the checks →

  • billing-sync-checker

    Finds places where the app's record of who has paid drifts from the payment provider over time: out-of-order webhook events, renewals that cannot be matched to a user, subscription statuses handled wrong, double billing, cancellations that cut access too early, no resync after a missed webhook and currency conversion mistakes.

  • payment-reliability-checker

    Finds payment code that fails silently or twice under real conditions: charges and refunds that can be sent twice, provider list calls that read only the first page, unpinned API versions, no record of payment events, swallowed payment errors and card declines users cannot recover from.

2 agents · see the checks →

  • legal-writer

    Checks whether a project has the privacy policy, terms, refund policy, business details and AI disclosures it needs, and writes those pages from what the code really does.

  • privacy-compliance-checker

    Checks the practical privacy basics in the code: tracking before consent, marketing email consent, personal data sent to third parties or written to logs.

SEO

3 agents · see the checks →

  • seo-checker

    Checks the technical SEO basics a site needs to be found: titles and descriptions, sitemap, robots.txt, canonical addresses, link previews, not-found pages and broken links.

  • schema-writer

    Checks a site's structured data (JSON-LD) for errors and invented claims, and writes correct Schema.org markup for the pages that benefit.

  • ai-search-checker

    Checks whether AI answer engines such as ChatGPT, Claude, Perplexity and Google AI Overviews can crawl, read and accurately describe a site.

Speed and quality

3 agents · see the checks →

  • speed-checker

    Finds what makes a site slow to load and slow to respond: heavy images, oversized JavaScript, render-blocking scripts, fonts and uncached pages.

  • accessibility-checker

    Checks a site for common barriers to people using a keyboard, a screen reader or with low vision: missing labels, poor contrast, hidden focus, clickable divs and inaccessible pop-ups.

  • mobile-checker

    Checks that a site works on phones: viewport, layouts that fit narrow screens, tap targets, readable text and usable forms.

Reliability

3 agents · see the checks →

  • error-tracking-setup

    Checks whether errors are reported, handled and logged safely, and sets up an error tracking service when asked.

  • backup-checker

    Checks whether the database and uploaded files are backed up, whether hosting plans could pause or drop the project, and whether anything alerts the owner when the site goes down.

  • deploy-checker

    Checks that a project is configured to run correctly in production: environment variables, build health, host limits, domain and callback addresses, and email delivery setup.

Reliability, production

2 agents · see the checks →

  • resilience-checker

    Finds code that turns a slow or failing service, a second server instance or a restart into an outage or lost work: outside calls with no timeout, background work that is silently dropped, retry storms, failed jobs that vanish, scheduled jobs that run twice, in-memory state on multi-instance hosts, no graceful shutdown and memory that grows without limit.

  • release-safety-checker

    Finds what makes deploying a new version risky: shared caches that serve one user's page to another, database changes that break the running or previous version, open browser tabs that break after a deploy, live connections the host cuts, risky features with no off switch and no check after deploy.

Launch

3 agents · see the checks →

  • launch-writer

    Writes launch material in the maker's own voice: Product Hunt listing and first comment, X announcement and thread, Reddit posts per community, and a tailored launch-day checklist.

  • landing-page-reviewer

    Reviews a landing page's words, structure and email capture as a first-time visitor would: is it clear what the product is, who it is for, why to trust it and what to do next.

  • analytics-setup

    Checks whether a site measures visits, signups and purchases, and sets up privacy-friendly analytics with the key events when asked.

/launch-check

Find the problems before your users do.

Install the kit into Claude Code, type one command, and get a score and a list of what to fix. Pay once, use it on every project you own.

41 agents · 440 checks · read-only audit · one-time payment