Security
Security checks for apps built with Claude Code
Leaked keys, open routes and users reading each other's data, found before launch.
Most security holes in a new app are not clever attacks. They are a secret key in browser code, an API route that never checks who is calling, or a record that anyone can open by changing a number in the address.
Ten specialist agents each take one of these: secrets, git history, login, rate limits, access control, uploads, injection, headers, dependencies and AI features. Every finding names the file and line, what could happen, and the fix.
- 88
- Checks
- 10
- Agents
- 11
- Commands
Some of what it looks for
AUTH-01criticalPrivate pages or API routes are protected only in the browser, not on the serverAUTH-02criticalLogin tokens are not verified properly (decoded without checking, weak or hardcoded signing secret)LLM-02criticalThe AI can trigger actions (change data, send messages, spend money) and the code carries them out without its own permission checkRESET-01criticalReset tokens or codes are guessableRESET-03criticalThe reset endpoint changes the password for whatever user ID or email the request namesKEY-01criticalA secret key is written directly in the source codeKEY-02criticalA secret is in an environment variable that the framework sends to the browserKEY-03criticalThe Supabase `service_role` key or a Firebase Admin key is used in browser code
These are 8 of the 88 checks in this area, worst first.
The agents that do the work
secrets-hunterFinds leaked API keys, passwords and tokens in source code, public environment variables, config files and build output.
git-history-scannerSearches a repository's git history for secrets and .env files that were committed in the past and can still be recovered, and checks whether the repository is public.
auth-checkerReviews login, signup, sessions and password reset to find ways someone could reach private data without logging in or get into an account that is not theirs.
rate-limit-checkerChecks that login, signup and costly endpoints limit how often they can be called, so nobody can guess passwords at speed or run up the owner's bill on paid services such as AI models, email and SMS.
access-control-checkerWorks out who is allowed to do what in an app, then finds where someone can reach another user's or another team's data, give themselves more rights, or use an admin function.
upload-checkerChecks that file uploads are limited by type and size, saved under safe names, and not readable by the wrong people.
injection-hunterLooks for places where user or AI-generated input can change a database query, run a command, read files, make the server fetch other addresses, or run scripts in other users' browsers.
headers-checkerChecks the security headers a site sends, which other websites may call its API (CORS), protection against forged requests, and debug information leaking in production.
dependency-auditorAudits a project's packages for known security holes, fake or misspelled package names, missing lockfiles and outdated frameworks.
ai-abuse-checkerReviews how an app talks to AI models, to find ways a user could make the AI ignore its instructions, act on other users' data, leak what it was told, or be used at the owner's expense.
The commands you type
/launch-securityAll security checks
/check-secretsLeaked keys in code, config files and build output
/check-git-historyKeys and `.env` files still recoverable from old commits
/check-authLogin, sessions, password reset, routes that work without logging in
/check-rate-limitsAttempt limits, and paid services (AI, email, SMS) anyone can run up
/check-accessCan users reach each other's data? Are admin features protected?
/check-uploadsFile type and size limits, safe storage, private files
/check-injectionSQL injection, command injection, cross-site scripting
/check-headersSecurity headers, CORS, debug leaks in production
/check-depsVulnerable, fake or outdated packages
/check-ai-abusePrompt injection, AI tools without permission checks, leaked instructions
/launch-check
Find the problems before your users do.
Install the kit into Claude Code, type one command, and get a score and a list of what to fix. Pay once, use it on every project you own.
41 agents · 440 checks · read-only audit · one-time payment