Deterministic rules
Shared rule engine patterns for hardcoded keys, JWT secrets, exposed DB URLs, and common auth mistakes.
Solutions · AI code security
Cursor, Lovable, Bolt, and other AI builders ship fast. Release Check surfaces secrets, auth gaps, risky dependencies, and configuration issues in the code you actually have — then labels whether the result is local preview or stronger evidence.
Shared rule engine patterns for hardcoded keys, JWT secrets, exposed DB URLs, and common auth mistakes.
Useful when generated clients put service keys or open data policies into front-end code.
Verified / Review required / Blocked for the explicitly checked scope — not a vanity score alone.
[SIGNAL] CRITICAL — Supabase service_role pattern in browser bundle [SIGNAL] HIGH — JWT secret assigned in source [RELEASE] Review required — 2 critical findings in checked files
No. It works on any supported source. AI-built apps are a common entry path because they ship quickly with repeated secret and RLS mistakes.
Scan metadata paths are designed not to retain full raw source. Local browser checks keep code in your browser unless you use a signed-in recorded workflow.
No. Results are evidence of performed checks for stated scope — not a guarantee the system is free of all vulnerabilities.