一个 Claude Code 技能,用于审计 AI 构建的应用在五个领域(前端、后端、认证、基础设施、运维)的生产就绪程度,提供评分卡和可复制粘贴的修复方案。

Stars

87

7 天增长

暂无数据

Fork 数

56

开放 Issue

0

开源协议

MIT

最近更新

2026-07-22

AI 仓库情报摘要
FR-AI / ANALYSIS

为什么值得关注

它填补了使用 AI 编程工具但缺乏安全背景的开发者的关键空白,提供结构化的、感知技术栈的审计,能反驳用户的合理化借口,使用固定评分规则保证一致性,并通过基于证据的访谈而非简单自我报告来验证。

适合谁使用

  • 使用 Lovable、Bolt、v0、Cursor 或 Claude Code 构建应用但缺乏安全背景的开发者
  • 独立开发者或 solo 创始人,即将发布第一个生产应用
  • 对生产加固缺乏认知的初级开发者
  • 需要可重复、感知技术栈的预发布安全检查清单的团队

典型使用场景

  • AI 构建的 Web 应用上线前的生产就绪度检查
  • 针对 Supabase、Firebase 或 Next.js 应用的安全加固审计
  • 开发后审查,捕获常见的高成本漏洞(如禁用 RLS、缺少限流)
  • 迭代评分循环,跟踪从 0/5 到 5/5 各领域通过的进展

项目优势

  • 不依赖特定技术栈,自动检测框架和后端(Next.js、Supabase、Firebase、Prisma 等)
  • 针对主要漏洞(如 RLS 策略、限流器、安全标头)提供可复制粘贴的修复手册
  • 固定的、可重复的评分规则,覆盖 5 个领域,区分严重/高/中/低,不同于自由形式的 AI 审查
  • 基于证据的访谈阶段要求命令行输出而非用户口头确认,拒绝将无法验证的项目标记为通过

使用前须知

  • 需要 Claude Code 环境(终端 + Claude CLI)并手动设置 git 才能运行审计
  • 无法自动修复密钥、数据库设置或 DNS;这些需要用户手动操作
  • 不是渗透测试——通过所有领域只代表不是容易攻击的目标,不代表不可攻破

README 快速开始

launchworthy

A Claude Code skill that plays bouncer at the door of production. Your app doesn't get in front of real users until it passes the check.

You built an app with Lovable, Bolt, v0, Cursor, or Claude Code. It works on your screen. This audits the five domains between "works for me" and "real users are paying for this and nothing is on fire," gives you a scored scorecard, and hands you a prioritized punch list with exact file paths and copy-paste fixes. The scorecard answers one question: is this app launchworthy yet?

It is stack-agnostic. It auto-detects your framework (Next.js, TanStack Start, SvelteKit, Svelte, Vite + React, Astro, Remix, and more) and your backend (Supabase, Firebase, Prisma, Directus, raw SQL) and adapts every check to what you actually use.

Why not just ask Claude?

The fair first question, so it goes first. Claude already knows what RLS is, what a rate limiter looks like, and why secrets do not belong in a client bundle. The knowledge was never the gap. What a raw "review my code" session does not give you:

  1. The scope you did not know to ask for. "Review my code" gets you a code review. It will not ask whether your backups have ever been restore-tested, whether error alerts actually reach you, whether you can roll back a bad deploy, or whether your domain registrar has 2FA. A third of this checklist is not in the code at all, and the person who most needs the audit is exactly the person who does not know to ask for those parts.
  2. A reviewer that refuses to reassure you. A chat model's default is to be agreeable. This skill's contract is not: anything it cannot verify is MANUAL CHECK NEEDED, never a pass. A domain whose critical check is unverified is capped at WARN. Your own "yes, that's fine" is recorded as reported by user, unverified; it never turns green on its own. And when you say "it's just an MVP," it argues back instead of nodding along.
  3. The same rubric twice. Ask a model to review your app twice and you get two differently shaped reviews. The fixed checklist, severities, and scoring rules are what make "0/5, fix the blockers, 5/5" a real progression you can watch, instead of vibes that shift every run.
  4. Judgment calls settled in advance. Generic AI reviews routinely flag the Supabase anon key

项目描述

A Claude Code skill that plays bouncer at the door of production: audits AI-built apps (Lovable, Bolt, v0, Cursor) across 5 domains and hands you a scored punch list with copy-paste fixes. MIT.

相关仓库与替代方案

根据分类、Topic 和编程语言匹配的相似项目。

0xwilliamortiz
精选
0xwilliamortiz GitHub avatar

ponytail-improved

Ponytail is a plugin for AI coding agents that enforces a disciplined ladder of reuse before writing code, reducing code volume by roughly 54% while preserving safety.

AI 与机器学习AI 智能体
545
makecindy
精选
makecindy GitHub avatar

cindy

Cindy is an open-source AI agent that runs locally on your machine, integrates multiple AI harnesses and models, and provides memory, skills, and automation to perform real work in your projects and apps.

AI 与机器学习大语言模型
958
0xwilliamortiz
精选
0xwilliamortiz GitHub avatar

openclaude-improved

OpenClaude is an open-source CLI coding agent that runs on any platform and supports a wide range of LLM providers, offering the same tools and workflows as Claude Code.

AI 与机器学习大语言模型
577