Is your AI-built app ready to launch?
An agent skill, a secret scanner and a 55-item checklist that audit your app before real users do.
Free. MIT licensed. Works with Claude Code and Codex.
Install the skill in 2 minutes
Three steps. The installer copies local files only. No network, no sudo.
Clone the repo
git clone https://github.com/First-Mate-Technologies/ai-app-production-checklist cd ai-app-production-checklistInstall the skill for your agent
Claude Codebash scripts/install-skill.sh claudeInstalls the skill into ~/.claude/skills/
Codexbash scripts/install-skill.sh codexInstalls the skill into ~/.agents/skills/
Add
--projectto install into the current folder instead.Restart your agent, open your app's folder, and ask
No agent? Run the scanner.
Needs Node 20 or newer. Run it from your app's folder.
npx github:First-Mate-Technologies/ai-app-production-checklist .Supabase? Paste the audit.
Paste sql/supabase-rls-audit.sql into the Supabase SQL editor and run it. It only reads system catalogs. Every row it returns is something to look at.
What you get back
Each prompt ends with a file you can read, share and work through.
- You ask“is my app ready to launch?”
- You getBlockers first, in PRODUCTION_READINESS.md
- You ask“check my Supabase RLS”
- You getAn access review you can verify in your own database
What's inside
Three parts. Use one or all of them.
- Agent skill
Production readiness
Ask "is my app ready to launch?" Your agent detects your stack, runs the scanner, checks 55 items against your real code, and writes PRODUCTION_READINESS.md with file:line evidence. Blockers come first.
- Secret scanner
One command, no setup
A small Node script that finds service-role keys in front-end code, committed .env files and unverified Stripe webhooks. No dependencies, no network, and it never prints a full secret.
npx github:First-Mate-Technologies/ai-app-production-checklist . - SQL and checklist
Supabase RLS audit and 55 checks
One read-only query for the Supabase SQL editor finds tables with Row Level Security off and policies that trust user-editable data. CHECKLIST.md covers data, auth, payments, errors, tests, performance, deploys and launch day.
How the audit works
Everything is read-only. The agent shows you what it found, with evidence. You decide what gets fixed.
Illustrative output, not a real app.
What it won't do
We would rather you know the limits now than find them the hard way.
It is not a security audit
The scanner and checklist are heuristics. A clean scan means those mistakes are not there. It does not mean the app is ready.
It reads your code and changes nothing
Read-only by default. It asks before it edits a file or touches your database.
It never prints a full secret
Findings name the file, the line and the kind of key. Values are masked, with at most the first four characters shown.
It leaves your database alone
You paste the SQL audit yourself. The agent only connects if you hand it an explicit read-only connection.
It does not read your git history
A key you committed once and deleted is still exposed. Rotate it. The scanner will not see it.
It cannot test a running app on its own
Rate limits, race conditions and webhook retries need a running app. The checklist lists them so you can test them before launch.
FINISH kit: FAQ
Is it free?
Yes. The kit is MIT licensed. Clone it, copy it, hand it to your team.
Does my code leave my machine?
The scanner runs locally and makes no network calls. The skill runs inside the AI agent you already use, so your code goes only where it already goes when you use that agent. First Mate never receives it.
Which stacks does it work with?
It is built for apps made with Lovable, Bolt, Replit, Cursor and v0, usually React or Next.js with Supabase and Stripe. The scanner checks Supabase and Stripe patterns. The checklist and the skill apply to any backend, and items that do not apply are marked N/A.
What if it finds a lot?
Start with the blockers. The report lists them first, each with the file, the line, why it matters and a concrete fix. Work the first three checklist sections (data, auth, payments) before anything else. If it is more than you want to take on, we can help.
Do I need Claude Code or Codex?
No. The scanner is a Node script (Node 20 or newer), the SQL audit is a paste into the Supabase editor, and the checklist is a Markdown file. Only the skill needs an agent.
Want a second pair of eyes?
Thirty minutes, free. Bring the app and we will tell you what we see.
Start your two-week trial.
No long-term commitment. Most engagements start with a low-risk trial. Prefer to talk first? Reach us directly.