Example report

Every finding tells you where, why and how to fix it.

No vague warnings. This is what you see in Claude Code after a check, for a made-up app scored by the kit's own rules. The same report is saved in your project as a file.

claude · my-app

/launch-check

  • Wave 1 · Security · 1 problem
  • Wave 2 · Database, Payments · 3 problems
  • Wave 3 · Reliability, Legal · 1 problem
  • Wave 4 · SEO, Speed and quality, Launch · 5 problems

Launch score39/ 100DON'T SHIP

A critical problem caps the score at 39.

2 critical2 high6 medium0 low

What this means

Do not launch yet. Any signed-in user can act as an admin, and the files your users upload can be opened by anyone. Both are quick to fix. After that, a payment can be counted twice and login will break on the live address.

Scores by area

Every area starts at 100 and loses points for each problem.

  • Security80
  • Database80
  • Payments89
  • Reliability92
  • Legal100
  • SEO94
  • Speed and quality94
  • Launch97

Fix these first

The critical and high problems, worst first.

  1. 1.

    [critical] AUTH-01 Admin API trusts client-provided role

    app/api/admin/users/route.ts:42

    Why: The route reads the user's role from the request instead of looking it up. Any signed-in user can call it as an admin and read or change every account.

    Fix: Read the role from the session on the server and refuse the request when it is not an admin.

    Security · takes minutes

  2. 2.

    [critical] STOR-01 Uploaded files are publicly readable

    supabase/migrations/0004_storage.sql:11

    Why: The uploads bucket is public, so anyone with a file's address can open it. Invoices and ID photos uploaded by your users are in it.

    Fix: Make the bucket private and hand out short-lived signed links to the file's owner.

    Database · takes minutes

  3. 3.

    [high] HOOK-03 Webhook accepts duplicate events

    app/api/webhooks/payments/route.ts:28

    Why: Payment providers send the same event more than once. Each copy adds credits again, so one payment can be paid out several times.

    Fix: Store the ID of every event you have handled and skip the ones you have already seen.

    Payments · takes hours

  4. 4.

    [high] DNS-03 Production callback points to localhost

    .env.production:7

    Why: After signing in, users are sent to an address that only exists on your laptop. Login will fail for everyone on launch day.

    Fix: Set the callback address to your live domain here and in the login provider's dashboard.

    Reliability · takes minutes

Fix these next

Medium and low problems.

  • [medium] HOOK-05 Webhook reports success even when it failed

    Fix: Answer with an error when handling fails, so the provider sends the event again. (minutes)

  • [medium] NF-01 Missing pages answer with status 200

    Fix: Return a real 404 for addresses that do not exist. (minutes)

  • [medium] ROBOT-02 There is no robots.txt

    Fix: Add one that allows the public pages and names the sitemap. (minutes)

  • [medium] BUNDLE-01 A charting library loads on every page

    Fix: Load it only on the dashboard page that draws charts. (hours)

  • [medium] MOB-02 The pricing table scrolls sideways on phones

    Fix: Let the table stack into rows on narrow screens. (minutes)

  • [medium] LAND-02 The landing page never says who the product is for

    Fix: Name the audience in the first screen. (minutes)

What looks good

  • Legal: no problems found in the 41 checks that ran.

Next step

Run /launch-fix to fix the problems, worst first. Then run /launch-check again to see the new score.

8 of the 10 fixes take minutes, 2 take hours.

Full report saved to .launchreadykit/report.md

/launch-check

Find the problems before your users do.

Install the kit into Claude Code, type one command, and get a score and a list of what to fix. Pay once, use it on every project you own.

41 agents · 440 checks · read-only audit · one-time payment