|
| 1 | +# Vibe App Launch Safety Sprint |
| 2 | + |
| 3 | +The Vibe App Launch Safety Sprint is a small public-repo service for builders shipping AI-assisted apps, agent tools, MCP servers, and fast launch prototypes. |
| 4 | + |
| 5 | +It focuses on obvious public-repo indicators that are easy to miss when an app is built quickly: leaked-secret patterns, risky environment examples, missing security basics, agent prompt exposure, GitHub Actions review prompts, wildcard CORS hints, webhook verification reminders, and public-readiness hygiene. |
| 6 | + |
| 7 | +This is a lightweight launch/readiness review. It is not a certified penetration test, compliance attestation, legal advice, or guarantee that a repository is secure. |
| 8 | + |
| 9 | +## Who It Is For |
| 10 | + |
| 11 | +- Solo founders preparing a public launch. |
| 12 | +- Indie hackers using Lovable, Bolt, Replit, Cursor, Codex, Claude Code, or similar tools. |
| 13 | +- Developers publishing MCP servers, agent skills, or agent-driven workflows. |
| 14 | +- Small teams that need a quick outside review before sharing a public repo. |
| 15 | + |
| 16 | +## Offers |
| 17 | + |
| 18 | +### USD 49 Mini Audit |
| 19 | + |
| 20 | +A report-only review for one public GitHub repository. |
| 21 | + |
| 22 | +You get: |
| 23 | + |
| 24 | +- One concise markdown report. |
| 25 | +- Public-repo checks for obvious leaked-secret patterns. |
| 26 | +- Launch-readiness checks for README, license, security policy, gitignore, CI, dependency metadata, and environment examples. |
| 27 | +- Agent/MCP/skill risk notes when relevant. |
| 28 | +- Vibe-app risk hints such as frontend-exposed secret names, Supabase service-role confusion, wildcard CORS, and webhook signature review prompts. |
| 29 | +- Prioritized next actions with redacted evidence. |
| 30 | + |
| 31 | +### USD 199+ Fix Sprint |
| 32 | + |
| 33 | +A bounded follow-on sprint after a mini audit is delivered. |
| 34 | + |
| 35 | +Best fit: |
| 36 | + |
| 37 | +- A few concrete repo fixes can improve launch readiness. |
| 38 | +- The fix can be done in a public PR or patch set. |
| 39 | +- The scope is small enough to define before work starts. |
| 40 | + |
| 41 | +The starting price is USD 199. Final scope and price are confirmed after the report, because not every repo has the same fix surface. |
| 42 | + |
| 43 | +## Validation Slots |
| 44 | + |
| 45 | +A few free validation slots may be offered to strong public-fit repos while FreeCodex validates the workflow. These are limited exceptions, not the standard paid offer. |
| 46 | + |
| 47 | +## Payment Timing |
| 48 | + |
| 49 | +First-contact outreach never includes payment links. Payment details are shared only after a positive reply, scope confirmation, and consent to proceed. |
| 50 | + |
| 51 | +## Turnaround |
| 52 | + |
| 53 | +Typical mini-audit turnaround is 24-48 hours after the public repo URL, intake context, and payment status are confirmed, subject to current queue. |
| 54 | + |
| 55 | +## Boundaries |
| 56 | + |
| 57 | +The standard offer is for public GitHub repos. Private repos are not part of the standard public-safe pack and require explicit permission plus separate scope confirmation. |
| 58 | + |
| 59 | +FreeCodex does not need credentials, account access, private keys, cookies, production access, or private repo access for the public mini audit. |
| 60 | + |
| 61 | +Do not send secrets or sensitive data. |
0 commit comments