vibe-audit

Free prompt highlights

Plan Mode_×

This prompt doesn't just write the plan.
It audits it until it holds up.

Stop getting plans that read like a paragraph. Read-only until you approve.

Morning Brief_×

Stop briefing Claude every morning.

An automated loop that reads your project files, surfaces what's unfinished, and drops a brief to your working folder before you even wake up. Runs while you sleep so you jump straight into the work.

Session Wrap_×

You're losing context every time you close a tab.
This catches it.

Paste it at the end of any Claude session, the decisions, what got dropped, what's still open, and a clean handoff for the next chat.

You shipped a SaaS in a weekend with Lovable, Bolt or Cursor. It works. You're three days from launch and the question that won't go away, what did the AI miss?

vibe-audit

PRE-LAUNCH SECURITY AUDIT

This kit answers that question. It's a curated audit your own AI coding tool runs against your codebase. No SaaS, scanner backend or source uploads. You drop the kit into your project, paste a prompt, and your AI walks through 25 findings one at a time, generates a report, and offers to apply fixes.

Buy on Gumroad — $49

  • FINDINGS25
  • SUPPLEMENTS05
  • PRICE$49
  • REFUND30 D
  • UPDATES12 M
THE GAP
shipped-anyway.log_×
  • 13,000 users exposed across 170 Lovable apps — CVE-2025-48757. Supabase ships Row Level Security disabled by default and the AI didn't turn it on.
  • 10.5% of AI-generated code is secure, though 61% is functionally correct — Carnegie Mellon's SusVibes study.
  • 2,000+ vulnerabilities and 400+ exposed secrets across 5,600 vibe-coded apps — Escape.tech.
PLATFORM SUPPLEMENTS

Each covers the specific defaults that bite on that platform.

  • LOVABLE Service-role-key-in-client problem. Supabase RLS disabled by default. The pattern behind CVE-2025-48757.
  • BOLT WebContainer-vs-deploy gap. Code that runs in the browser editor does not match what ships to production.
  • CURSOR Four documented IDE-level CVEs. The tool you're using to write the code has its own attack surface.
  • V0 Vercel env scope leakage between Preview and Production. Variables visible where they shouldn't be.
  • REPLIT Separate Secrets store for Deployments trap. Secrets in the editor don't automatically carry to deployed builds.
WHAT'S IN THE KIT
YOU-GET.txt_×

+ The 25-finding catalog with detection prompts and fix prompts

+ Five platform supplements (Lovable, Bolt, Cursor, v0, Replit)

+ A rules file template your AI reads on every turn to stop these patterns being created in the first place

+ A one-shot audit prompt that walks your AI through the catalog and writes a security report into your project

+ 12 months of updates as the patterns evolve and new platforms get added

YOU-DONT.txt_×

– A guarantee. No audit is exhaustive. This catches the patterns that have actually taken down vibe-coded apps in production. Real users and regulated data? Hire a pentester.

– A scanner. This isn't a service you upload code to. It runs locally in your own AI session. Your source never leaves your machine.

– A subscription. One-time purchase. Updates included for 12 months, then ongoing-access pricing announced before the 12-month mark.

HOW IT ACTUALLY WORKS
  1. STEP 1Buy the kit and download the zip.
  2. STEP 2Copy the contents of install/ into your project root. Two install modes — drop-at-root or @import from an existing rules file.
  3. STEP 3In a fresh AI session, paste: "Run the security audit defined in AI-AUDIT-CHECKLIST.md. Go through each finding one at a time."
  4. STEP 4Your AI investigates finding by finding, writes a report into security/REPORT.md, and offers to apply fixes.

Typical audit takes 15 to 45 minutes depending on codebase size and how much your AI has to read.

WHO IT'S FOR
✓ FOR
  • + Developers who shipped with Lovable, Bolt, Cursor, v0, or Replit and haven't run a security check before going live with real users.
  • + Solo operators without a security background who are deploying apps with real users, real data, or payment flows.
  • + Multi-project operators who shipped an AI-built SaaS and want to know what the AI left behind before they go live.
× NOT FOR
  • – Anyone who needs a formal penetration test or audit trail for regulated data. This is the pre-launch sanity check, not the report-of-record. Hire a pentester.
  • – Teams with security budgets and pentesters already on retainer. Your needs are different.
  • – Anyone looking for prompt packs. This is operating infrastructure.
PRICING
  • Standalone$49
  • Loopstack OS add-on$19
  • Refund window30 days
  • Updates included12 months

The Loopstack OS is launching soon. Buyers receive an add-on code to your original purchase receipt.

QUESTIONS
#vibe-audit_×

<you> how do I actually run the audit?

<luckyd3v> you drop the kit into your project and paste one prompt. your own AI runs the audit against your code and writes the report back into the project.

<luckyd3v> the findings come with fixes, not just flags.

<you> which coding tools does it run in?

<luckyd3v> any tool that reads a project rules file at the root. Claude Code, Cursor, GitHub Copilot, Windsurf and Gemini CLI all have tested patterns in the kit.

<you> how is this different from the free GitHub repos?

<luckyd3v> the foundation overlaps with benavlabs/vibe-check (17 findings, MIT, attributed). beyond that: 8 findings original to this kit, 5 researched platform supplements with CVE citations, a packaged rules file + audit checklist, and 12 months of updates.

<luckyd3v> roughly 75% is original work. the rest is curation and rewriting of public material, attribution kept.

<you> does my code go anywhere?

<luckyd3v> no. everything runs inside your own AI session. the kit is a set of markdown files your AI reads next to your code. no SaaS, scanner backend or upload.

* you are now talking in #vibe-audit

> type a message_

Buy on Gumroad — $49

is vibe coding secure?not by default. the audit catches what AI code gets wrong before you ship — fixes included, not just flags.
does my code get uploaded anywhere?no. everything runs inside your own AI session. no SaaS, no scanner backend, no upload.
luckyd3v

STOP: 0x0000LUCK (0xD3V, 0x00, 0xFREE)

The code has escaped containment. Are you sure you want to ship now? (Y/N)

> GET THE AUDIT _