Vibecode Hardening Kit
I audited 40 apps built with the popular describe-it-and-ship-it tools. The scary stuff (leaked keys, exposed secrets) mostly wasn't there. But almost none of them locked the front door. Check yours in one click.
Runs in your browser. One request to your app, same as a normal visit. Nothing is stored or sent anywhere.
Browsers hide some cross-site response headers from JavaScript, so an in-page check can under-report. For the exact result, run check-headers.sh from the kit.
Pick where your app is deployed. Copy the block. Redeploy. Adjust the CSP allow-list to the domains your app actually calls.
snippets/supabase-rls.md. Worth doing even if your header score is an A.