Who this is for
Builders who want a service with a clear finish line, sold to a buyer who is easy to find: the founder or small business owner who just built an app with an AI tool and is about to put real customers in it.
The pitch writes itself because the risk is real. AI coding tools ship features, not compliance. The usual result is a database anyone can read, an analytics pixel firing on a health intake form, and a privacy policy that does not match what the code collects.
What you get at the end
- A deterministic scan of a repo against ten traps: open database and leaked keys, missing or wrong privacy policy, kids on the app, tracking before consent, marketing email rules, auto-renew disclosure, chatbots that never say they are AI, accessibility basics, user uploads without a takedown path, and an inventory of every third-party script and font.
- Every finding with
file:line, verified by hand, false positives dropped out loud. - A client report in plain English with fixes and templates, marked as an engineering checklist, not legal advice.
What it costs
- Your Claude plan and Python 3. The scanner is stdlib, offline, and finishes in about a second on a typical app.
- Read access to the client's repo. Nothing is uploaded anywhere.
- Two to three hours for the judgment pass and the report.
Build it
- Copy the
client-safety-auditskill into~/.claude/skills/. - Get the repo. A zip or read-only GitHub access is enough. Never ask for production database credentials.
- Run the scan:
python3 scripts/scan.py <repo> --md <repo>/.safety-audit/scan.md --json <repo>/.safety-audit/scan.json. - Answer the intake questions the scan could not: who the users are, whether there is health data, whether EU users sign up, who sends marketing email.
- Open every FAIL and WARN at its line. Keep what is real, write down what is a false positive and why.
- Do the judgment checks the scanner marks REVIEW. The big one: read the privacy policy end to end against the tracker list. A policy that says "no analytics" while an analytics script loads is worse than no policy.
- Fill
templates/client-report.mdand hand it over with the fixes ranked by what could hurt them first.
Prompts to copy
Start the audit:
Run the client-safety-audit skill on ./client-repo. Scan first, then ask me only
the intake questions the scan could not answer. Verify every FAIL and WARN by
opening the file at the line, and list false positives with the reason.
Do not change any code in the repo.
Write the client report:
Fill templates/client-report.md from .safety-audit/scan.json and my verified notes.
Plain English, no legal conclusions, "not legal advice" at the top. Rank fixes by
what could hurt the owner first: exposed data, then tracking and consent, then
everything else. For each fix, name the file and the template that helps.
Sell it
Sell a fixed-price audit with a clear deliverable, then offer to fix what you found and to keep watching it. As an example only: $350 for a one-repo audit, then fixes quoted from the report, then care from $75 a month that reruns the scan before every release. We have not sold a standalone audit yet; the price is a starting point.
Hi {name}, congrats on getting {app} built.
Before real customers sign up, I run a pre-launch check for the problems AI
coding tools tend to leave in: an open database, tracking before consent, a
privacy policy that does not match the app. You get a report with the file and
line for every issue and how to fix it. Fixed price, two days. Interested?
Where it breaks
- The scanner is high recall and heuristic. It will flag things that are fine. The value is in your verification pass; skip it and you hand a client a scary list of false alarms.
- It reads the working tree, not git history. A key committed and later deleted is still exposed; run
gitleakson the history too. - It is not legal advice and must never read like it. Anything about whether a law applies goes to the client's lawyer.
- Health care clients need more than this. If the app touches patient data, HIPAA rules apply and they are stricter than anything in the ten checks.
Receipts
HQ built this skill to check its own client apps before launch. It carries a test suite of fixture apps (a deliberately bad one, a clean one, and one full of cases only judgment can catch).
Prove it: python3 -m unittest discover -s tests inside the skill runs 33 tests against those fixtures.