Skip to content

Check your app free for 7 days

Your agent sends your code, and you get back a plain-English list of what to fix. After that it is $10.00 a month, and you can cancel anytime.

What the audit looks for

Your agent sends the files to be checked. They are read once and deleted when the answer comes back.

  • A door left open in the code

    Agents copy shortcuts from bad tutorials, like passing a stranger's text straight to your server. The audit finds those shortcuts.

  • A key left in your code

    Agents paste an AI or payment key straight into a file, or ship it to the browser. The audit names the file and says to replace the key first, because deleting the line does not undo a leak.

  • A database table anyone can read

    If your app uses Supabase, the audit reads the rules in your migrations and finds tables with no rules, rules that let anyone in, and a rule that lets a user upgrade their own plan.

  • A paid feature anyone can use for free

    Agents often check who has paid only in the browser. The audit finds API routes with no sign-in check, a price the browser can change, and payment webhooks nobody verifies.

  • Your agent said it works. Your client says it's broken.

    Some tests pass without checking anything. The audit finds them, so you know which green checkmarks to doubt.

  • A plugin that gives your secrets away

    A plugin can carry a password or key in its files. It can also talk to someone else’s server without protection.

  • Your agent is allowed to delete everything

    In Claude Code, one setting can let your agent run any command or delete files without asking. The audit names those settings.

  • A skill that works against you

    A skill can hide text that overrides your agent. It can also read your saved passwords or send your data somewhere else.

One plan, cancel anytime

$10.00/user/month

The first 7 days are free. Cancel before day 7 and you pay nothing.

It covers every check above, each time you ship. Cancel whenever you like and keep access to the end of what you paid for. Payments are handled by Polar.

Your AI model bill stays separate

The plan pays for the checks. The AI model your agent runs on is still billed by its own company, on your own account.

Works with the tools you already build in

Claude Code, Codex, Cursor, Antigravity, Replit, Lovable, Bolt, v0 and more. The code audit needs a tool that can open your project. From a chat app like Claude or Grok, you can check an installed skill, not your own code.

What the audit doesn’t catch

These are static checks: they read your code without running it. They can’t tell you whether one user can reach another’s data once the app is live.

They do look for the three risks that have hurt apps like yours most. Those are database tables left open to anyone, a leaked AI key running up a bill, and paid features used without paying. They read only the files you send, and only Supabase for the database. The free pre-ship checklist shows what to check by hand.

For developers
  • code_pattern_audit · CP001–CP025
  • secret_exposure_audit · KL001–KL006
  • supabase_rls_audit · SU001–SU010
  • paywall_enforcement_audit · PW001–PW009
  • vacuous_guard_audit · VG001–VG003
  • plugin_manifest_audit · PM001–PM013
  • settings_permission_audit · PX001–PX011
  • skill_security_audit · SK001–SK012

code_pattern_audit does not check for SQL injection; secret_exposure_audit is the secrets scanner, over the files you send. The checks are deterministic Layer 1 verifiers on content you send. Layer 2 is the generative agents and workflow prompts, run on your own model, metered per user.

ClientLayer 1 · verifiersLayer 2 · generativeWorkflow prompts
claude.ai connectorYes — send skill files inlineYes — via the generation contract, on your modelYes
Claude Code / Desktop (sampling)Yes — send skill files inlineYes — on your client's model via MCP samplingYes
Google Antigravity (M2M credential)Yes — send skill files inlineYes — via the generation contract, on your modelYes, per user
CI / custom harness (M2M credential)Yes, gated and metered per userYes — sampling when supported, contract otherwiseYes, per user

Entitlement is per person: sign in with the same email from claude.ai or Claude Code. For scripts and CI, create an API key in your account; it bills to the same subscription. An agent that should carry only Jackdaws can use the lean surface: fewer tools, same key, same price. The full surface at /mcp is unchanged.

Check your app before your clients do

Sign in, connect the tool you build with, and get your first list of fixes.