Security

Security checks for apps built with Claude Code

Leaked keys, open routes and users reading each other's data, found before launch.

Most security holes in a new app are not clever attacks. They are a secret key in browser code, an API route that never checks who is calling, or a record that anyone can open by changing a number in the address.

Ten specialist agents each take one of these: secrets, git history, login, rate limits, access control, uploads, injection, headers, dependencies and AI features. Every finding names the file and line, what could happen, and the fix.

88
Checks
10
Agents
11
Commands

Some of what it looks for

  • AUTH-01criticalPrivate pages or API routes are protected only in the browser, not on the server
  • AUTH-02criticalLogin tokens are not verified properly (decoded without checking, weak or hardcoded signing secret)
  • LLM-02criticalThe AI can trigger actions (change data, send messages, spend money) and the code carries them out without its own permission check
  • RESET-01criticalReset tokens or codes are guessable
  • RESET-03criticalThe reset endpoint changes the password for whatever user ID or email the request names
  • KEY-01criticalA secret key is written directly in the source code
  • KEY-02criticalA secret is in an environment variable that the framework sends to the browser
  • KEY-03criticalThe Supabase `service_role` key or a Firebase Admin key is used in browser code

These are 8 of the 88 checks in this area, worst first.

The agents that do the work

  • secrets-hunter

    Finds leaked API keys, passwords and tokens in source code, public environment variables, config files and build output.

  • git-history-scanner

    Searches a repository's git history for secrets and .env files that were committed in the past and can still be recovered, and checks whether the repository is public.

  • auth-checker

    Reviews login, signup, sessions and password reset to find ways someone could reach private data without logging in or get into an account that is not theirs.

  • rate-limit-checker

    Checks that login, signup and costly endpoints limit how often they can be called, so nobody can guess passwords at speed or run up the owner's bill on paid services such as AI models, email and SMS.

  • access-control-checker

    Works out who is allowed to do what in an app, then finds where someone can reach another user's or another team's data, give themselves more rights, or use an admin function.

  • upload-checker

    Checks that file uploads are limited by type and size, saved under safe names, and not readable by the wrong people.

  • injection-hunter

    Looks for places where user or AI-generated input can change a database query, run a command, read files, make the server fetch other addresses, or run scripts in other users' browsers.

  • headers-checker

    Checks the security headers a site sends, which other websites may call its API (CORS), protection against forged requests, and debug information leaking in production.

  • dependency-auditor

    Audits a project's packages for known security holes, fake or misspelled package names, missing lockfiles and outdated frameworks.

  • ai-abuse-checker

    Reviews how an app talks to AI models, to find ways a user could make the AI ignore its instructions, act on other users' data, leak what it was told, or be used at the owner's expense.

The commands you type

  • /launch-security

    All security checks

  • /check-secrets

    Leaked keys in code, config files and build output

  • /check-git-history

    Keys and `.env` files still recoverable from old commits

  • /check-auth

    Login, sessions, password reset, routes that work without logging in

  • /check-rate-limits

    Attempt limits, and paid services (AI, email, SMS) anyone can run up

  • /check-access

    Can users reach each other's data? Are admin features protected?

  • /check-uploads

    File type and size limits, safe storage, private files

  • /check-injection

    SQL injection, command injection, cross-site scripting

  • /check-headers

    Security headers, CORS, debug leaks in production

  • /check-deps

    Vulnerable, fake or outdated packages

  • /check-ai-abuse

    Prompt injection, AI tools without permission checks, leaked instructions

/launch-check

Find the problems before your users do.

Install the kit into Claude Code, type one command, and get a score and a list of what to fix. Pay once, use it on every project you own.

41 agents · 440 checks · read-only audit · one-time payment