Show HN: AI Shipcheck – know if your AI-built app is ready to ship AI Shipcheck, a new open-source static analysis tool released as v1.0.1, scans AI-generated code locally to flag production-readiness issues, scoring apps across nine categories and blocking deployment on critical findings. In a demo on a vulnerable Supabase app, it returned a NOT READY verdict of 61/100 across 41 checks, identifying a critical service-role key exposure and 7 database safety findings. The tool runs via `npx ai-shipcheck .` with no signup, API key, or source upload, and includes 63 rules with documentation and fixtures. Your AI says it's done. Shipcheck tells you if it's ready to ship. npx ai-shipcheck . No signup · No API key · No source-code upload · Runs locally NOT READY 61/100 across 41 assessed checks my-app Detected: Next.js, React, Supabase, Vitest, Next.js App Router · TypeScript · tests present Assessed: 41 of 63 checks run · 7/9 categories scored · 9 files · 3 not assessed Security ██████████░░░░░░ 60 1 finding Authentication & Authorization ████████░░░░░░░░ 52 2 findings Database & Data Safety ░░░░░░░░░░░░░░░░ 0 7 findings Reliability ████████████████ 98 1 finding Testing ███████████░░░░░ 71 3 findings Observability ███████████████░ 92 1 finding Performance ███████████████░ 92 3 findings Accessibility ················ not assessed AI Cost & Abuse Controls ················ n/a Findings CRITICAL BLOCKER Service-role key read through a browser-visible environment variable lib/supabase-admin.ts:5:27 │ process.env.NEXT PUBLIC SUPABASE SERVICE ROLE KEY , lib/supabase-admin.ts reads the Supabase service-role key from a variable with a public build-time prefix. The value is inlined into the browser bundle, granting every visitor full, RLS-bypassing access to the database. Fix: Use the anon key in the browser and rely on row-level security for access control. Keep the service-role key in server-only code - a route handler, server action, or edge function - and rotate it immediately if it has ever been in a client bundle. auth/supabase-service-role-exposure · confidence high · ai-shipcheck explain auth/… Verdict · 4 blocking issues must be fixed before deploying. A blocker forces NOT READY regardless of score. · Weakest category: Database & Data Safety at 0/100 7 findings . Scanned 9 files in 28 ms · 41 checks run, 19 not applicable, 3 not assessed · ai-shipcheck v1.0.1 Static analysis of source code - not a security certification. Real output from fixtures/vulnerable-supabase, trimmed for length. AI coding tools are very good at producing code that runs, and much less good at producing code that survives production. They report the work as finished either way. The gaps are consistent and boring: the Supabase table nobody enabled RLS on, the route handler that writes without checking who is calling, the NEXT PUBLIC variable holding a secret, the LLM endpoint with no rate limit and no token cap. Shipcheck looks for exactly those, statically, on your machine. Nine categories, scored independently. 63 rules , each with documentation, a vulnerable fixture, a secure fixture and tests. | Category | Examples | |---|---| Security | Hardcoded credentials, secrets behind NEXT PUBLIC , eval , shell injection, open redirects, permissive CORS, TLS verification disabled, weak crypto | Auth | Routes that write without an authorisation check, server actions with no auth, browser-only privilege checks, unverified webhooks, unsigned JWTs, exposed service-role keys | Database | Tables without row-level security, USING true policies, SQL built by interpolation, deletes with no filter, destructive migrations | Reliability | Swallowed errors, missing timeouts in request paths, unhandled rejections, retries with no backoff, builds set to ignore type errors | Testing | No tests, CI missing test/build/typecheck, .only committed, server code with no test referencing it | Observability | No error monitoring, console -only server logging, no React error boundary, handlers that swallow errors | Performance | Unbounded queries, synchronous I/O in request handlers, N+1 shapes, heavy client imports | Accessibility | Missing alt , click handlers on non-interactive elements, unlabelled form controls, positive tabIndex | AI cost | LLM endpoints with no auth or rate limit, no token cap, request-controlled model selection, provider keys in the browser | Full catalogue: docs/rules — or run ai-shipcheck rules . Stacks it understands: Next.js both routers , React, Vite, Express, Fastify, Hono, NestJS, Remix, Astro, SvelteKit, Nuxt, Supabase, Firebase, Prisma, Drizzle, Mongoose, Stripe, OpenAI, Anthropic, Vercel AI SDK, LangChain, tRPC, and the common test runners. Framework-specific rules run only when the framework is detected, monorepos included. npx ai-shipcheck . scan the current directory npx ai-shipcheck . --fail-on critical exit 1 when a critical finding exists npx ai-shipcheck . --format sarif also: json, markdown npx ai-shipcheck explain