Tool · for anyone building with Claude Code · any stack
Build your own security audit
A public scan takes two seconds and reads the surface. Under it lies the 90 to 99% no outside scan can reach, where breaches begin. Rarely with a targeted attack. Usually with a key committed by accident, a dependency left to rot, or a forgotten route nobody closed. Nobody looks, until the day everybody does.
A paste-ready prompt that hands your AI the same audit a security engineer would run. Node, Python, WordPress, Supabase, Vercel, a plain static site or a no-code build: it interviews you first, then adapts.
Haven’t run the free one yet? The Basic Scan checks 23 signals on your public surface, in two seconds, for nothing: encryption, security headers, DNS and email records, exposed files. Start there. This prompt is for everything the scan cannot reach.
What you are buying
A prompt that builds you an auditor
Point it at your codebase and it builds a custom agent skill, tuned to your own stack, that reads everything the surface scan cannot: your code, your dependencies, your auth, your secrets, your configuration. You get back a clear, graded report and the exact fixes.
You can then turn it into a scheduled routine that re-checks on its own and flags what is drifting, before it becomes a story you would rather not be in.
It is written in plain language and does the interview for you, so you do not need to be a security engineer to run it. You do need Claude Code and a project folder.
What the audit covers
- The OWASP Top 10 (2025)
- Dependency CVEs
- Secret scanning, git history included
- Licence compliance
- Prompt-injection surface
- Auth and access control
- File uploads and webhooks
- CI and deploy workflows
- Cost and abuse ceilings on metered endpoints
Every run produces a structured report, graded by severity with numeric thresholds, and compared against previous runs so you can watch the trend. Best used with the strongest model you have.
Why this matters
The surface is the least of it
Encryption and headers are the easy 1 to 10%. Leaked keys, broken access control and vulnerable dependencies live in the code no scanner outside your repo can see.
Fast to build is not safe to run
AI-built and vibe-coded apps launch in days — with the secret in the commit, the open endpoint and the dependency with a known CVE right alongside the feature.
One credential can undo the lot
A single exposed key or injectable prompt can drain a database, run up a cloud bill or leak your users’ data overnight. The blast radius rarely matches the size of the mistake.
It doesn't fix itself
Dependencies age, configuration drifts, secrets pile up. What was clean three months ago is not now, and nothing tells you unless something looks.
Scary because it is invisible
So make it visible. An audit turns the fog into a ranked list: what is actually wrong, how bad it is, and how to fix it. The fear becomes a to-do list you can clear.
Get clear results
The audit gives you an objective report, with clear information on what it covered and what it did not. A check that could not run is counted as a finding and said out loud, never buried in a footnote.
What it cannot see
A skill built this way audits the files in your project folder. That is powerful and it has a hard edge. It cannot see:
- Settings you changed in a dashboard (Cloudflare, Vercel, Railway, Netlify, your host’s control panel). A protection switched off there leaves no trace in your files.
- Your database rules if the database lives in a service like Supabase or Firebase. Those rules live in that service, not your code.
- Live behaviour: the actual headers your site sends, your DNS, your TLS certificate, your environment variables in production.
- Plugins and themes in a CMS like WordPress, where most of the risk lives and almost none of it is in a file you wrote.
The prompt makes the skill say all of this out loud, every run. A “0 findings” report means “nothing bad in the files I could read”, never “you are safe”.
Get the prompt
€29
One payment. Yours for as long as we host it, with updates included.
- The full prompt, ready to paste into Claude Code
- Eight staged instructions: discovery, safety rules, checks, grading thresholds, scope honesty, report format, self-verification, house style
- The setup notes: which model to use, what to answer, what to do with the first report
- A page you keep, with a copy button, plus the Markdown file by email
- Licensed for your own projects, including client work you do yourself
Enter the email you bought with and we will re-send it.
Licence: for the buyer’s own projects, including client work you carry out yourself. Please don’t redistribute or resell the prompt itself.
Digital content, delivered immediately. The 14-day right of withdrawal and what you waive by buying are set out in full in the terms, which you accept at checkout. If the file does not arrive, or it is not what this page described, write to [email protected] and we will put it right.
This prompt builds a tool that gives recommendations. It is not a security certification, a penetration test, or a guarantee that your project is safe. See the terms and privacy policy.