The FINISH kit

Is your AI-built app ready to launch?

An agent skill, a secret scanner and a 55-item checklist that audit your app before real users do.

Free. MIT licensed. Works with Claude Code and Codex.

Install the skill in 2 minutes

Three steps. The installer copies local files only. No network, no sudo.

  1. Clone the repo

    git clone https://github.com/First-Mate-Technologies/ai-app-production-checklist
    cd ai-app-production-checklist
  2. Install the skill for your agent

    Claude Code
    bash scripts/install-skill.sh claude

    Installs the skill into ~/.claude/skills/

    Codex
    bash scripts/install-skill.sh codex

    Installs the skill into ~/.agents/skills/

    Add --project to install into the current folder instead.

  3. Restart your agent, open your app's folder, and ask

No agent? Run the scanner.

Needs Node 20 or newer. Run it from your app's folder.

npx github:First-Mate-Technologies/ai-app-production-checklist .

Supabase? Paste the audit.

Paste sql/supabase-rls-audit.sql into the Supabase SQL editor and run it. It only reads system catalogs. Every row it returns is something to look at.

What you get back

Each prompt ends with a file you can read, share and work through.

You ask“is my app ready to launch?”
You getBlockers first, in PRODUCTION_READINESS.md
You ask“check my Supabase RLS”
You getAn access review you can verify in your own database

What's inside

Three parts. Use one or all of them.

  • Agent skill

    Production readiness

    Ask "is my app ready to launch?" Your agent detects your stack, runs the scanner, checks 55 items against your real code, and writes PRODUCTION_READINESS.md with file:line evidence. Blockers come first.

  • Secret scanner

    One command, no setup

    A small Node script that finds service-role keys in front-end code, committed .env files and unverified Stripe webhooks. No dependencies, no network, and it never prints a full secret.

    npx github:First-Mate-Technologies/ai-app-production-checklist .
  • SQL and checklist

    Supabase RLS audit and 55 checks

    One read-only query for the Supabase SQL editor finds tables with Row Level Security off and policies that trust user-editable data. CHECKLIST.md covers data, auth, payments, errors, tests, performance, deploys and launch day.

How the audit works

Everything is read-only. The agent shows you what it found, with evidence. You decide what gets fixed.

How the production readiness audit worksFive steps. Your code goes through the scanner, which looks for leaked keys and open tables. The agent then checks 55 checklist items and records file and line evidence. It writes PRODUCTION_READINESS.md with blockers first. You confirm which fixes to make before anything changes.1Your coderepo, routes,schema, env files2Scannerleaked keys,open tables3Checklist check55 items, each withfile:line evidence4ReportPRODUCTION_READINESS.mdblockers first5You confirm fixesnothing changeswithout your yes

Illustrative output, not a real app.

What it won't do

We would rather you know the limits now than find them the hard way.

  • It is not a security audit

    The scanner and checklist are heuristics. A clean scan means those mistakes are not there. It does not mean the app is ready.

  • It reads your code and changes nothing

    Read-only by default. It asks before it edits a file or touches your database.

  • It never prints a full secret

    Findings name the file, the line and the kind of key. Values are masked, with at most the first four characters shown.

  • It leaves your database alone

    You paste the SQL audit yourself. The agent only connects if you hand it an explicit read-only connection.

  • It does not read your git history

    A key you committed once and deleted is still exposed. Rotate it. The scanner will not see it.

  • It cannot test a running app on its own

    Rate limits, race conditions and webhook retries need a running app. The checklist lists them so you can test them before launch.

FINISH kit: FAQ

Is it free?

Yes. The kit is MIT licensed. Clone it, copy it, hand it to your team.

Does my code leave my machine?

The scanner runs locally and makes no network calls. The skill runs inside the AI agent you already use, so your code goes only where it already goes when you use that agent. First Mate never receives it.

Which stacks does it work with?

It is built for apps made with Lovable, Bolt, Replit, Cursor and v0, usually React or Next.js with Supabase and Stripe. The scanner checks Supabase and Stripe patterns. The checklist and the skill apply to any backend, and items that do not apply are marked N/A.

What if it finds a lot?

Start with the blockers. The report lists them first, each with the file, the line, why it matters and a concrete fix. Work the first three checklist sections (data, auth, payments) before anything else. If it is more than you want to take on, we can help.

Do I need Claude Code or Codex?

No. The scanner is a Node script (Node 20 or newer), the SQL audit is a paste into the Supabase editor, and the checklist is a Markdown file. Only the skill needs an agent.

Want a second pair of eyes?

Thirty minutes, free. Bring the app and we will tell you what we see.

Get started

Start your two-week trial.

No long-term commitment. Most engagements start with a low-risk trial. Prefer to talk first? Reach us directly.

By submitting, you agree we may contact you about our services. Unsubscribe anytime. See our Privacy Policy.