Your app works. Whether it's safe to launch is a different question, and "the AI said it added security" is not an answer.
The Ship Check Kit is 42 launch and security checks your coding agent runs on an app built with Lovable, Bolt, Cursor, Claude Code, v0 or Replit. It tests your code, your live site and your Supabase or Firebase project, then writes a report with a verdict, the evidence behind every result, and the fix for every failure.
Not useful? Message @zephosdev on X within 14 days for a refund.
$ /ship-check
FAILSC-SEC-01 secrets in git history
FAILSC-RLS-02 anon key reads profiles
FAILSC-RLS-04 users can set plan='pro'
FAILSC-PAY-01 unsigned webhook accepted
WARNSC-PAY-03 no duplicate-event check
PASSSC-CORS-01 no arbitrary origins
DON'T LAUNCH· evidence in SHIP-CHECK.md
Excerpt from a run on our deliberately broken sample app.
42 checks, three tiers. 20 that should block a launch, 14 for your first week, 8 before a business customer sends a security questionnaire.
Runs where you already work./ship-check in Claude Code, @ship-check in Cursor, or plain terminal recipes.
Stable check IDs.SC-RLS-02 means the same thing to you, your agent and your co-founder.
Read-only by default. It doesn't change your code until you ask it to.
02
What you download
A zip with the 42 checks (CHECKS.md and JSON), a Claude Code skill and a Cursor rule (plus /ship-check-rls for Supabase data isolation), ten terminal recipes, a report template, one-page guides for five stacks, and a worked example: a deliberately broken sample app, its report, the fixed version and its re-run. 12 months of updates.
$29 · one-time
Ship Check Kit
One-time payment via Stripe. Instant download. Support is a DM to @zephosdev on X.