VibeRaven Guides

호스팅된 읽기 전용 서비스로, 로그인 없이 사용 가능합니다 (https://viberaven.dev/mcp). VibeRaven의 파인딩 ID를 설명하고 Vercel + Supabase 앱용 실행 가이드와 체크리스트를 제공합니다. 저장소를 읽지 않습니다.

호스팅형 MCP 서버

npx add-mcp 'https://viberaven.dev/mcp'

Claude Code, Codex, Cursor 등에 설치됩니다

문서

repo

github.com/you/your-app

DetectedReady

web

your-app.vercel.app

Env vars documentedReady

payments

Stripe

Webhook handler foundReady

auth

Auth.js

Auth secret setReady

database

public.posts

RLS on · owner policiesReady

monitoring

Sentry

Errors trackedReady

Services

cacheemail

Sample app. Finding ids are real VibeRaven checks.

your-app

No blockers found

npx -y viberaven

Sample stack. Checks and detections are real VibeRaven output.

  • Finds your stack

    Reads the repo and names every service the app runs on.
  • Checks each piece

    Row level security, webhooks, secrets, env vars, rate limits and monitoring.
  • Hands the fix to your agent

    A task list for Claude Code, Codex or Cursor to work through.

Anyone anon key

id user_id body created_at

rls_disabled · critical Anyone holding the anon key your frontend ships can read and change these rows.

75 score · 1 blocker

01It reads the repo and flags a table anyone can read.

viberaven check

viberaven check · ~/posts-app

No RLS policy proof in migrations (rls_disabled)

1 public table without row level security: public.posts (supabase/migrations/0001_posts.sql:1). Anyone holding the anon key your frontend ships can read and change those rows through the Data API.

No error monitoring detected (missing_monitoring)

No Sentry/PostHog (or similar) instrumentation was found. Production errors will only surface when users complain.

Verdict: 1 blocker, 0 warnings · score 75

Fix: viberaven fix · Details: ~/posts-app/.viberaven/agent-tasklist.md

Step 1 of 3: Scan. It reads the repo and flags a table anyone can read.

Output captured with viberaven 1.6.1. We wrote the migration by hand for this demo.

  • Open tables

    Supabase tables with no row level security. rls_disabled
  • Exposed keys

    Secret files not gitignored. The service role key in client env or code. secrets_in_repo service_role_key_in_client_env service_role_key_in_client_code
  • Unsigned sessions

    Auth.js with no auth secret referenced. auth_secret_missing
  • Silent payments

    Stripe with no webhook handler. missing_stripe_webhook
  • Missing env vars

    Vars your code reads that.env.example lacks. env_var_drift
  • No guard rails

    No rate limits. No error monitoring. missing_rate_limit missing_monitoring

Studio

$0 open source

The local Studio on your machine. Every local check, every provider card, your own coding agent. No account needed.

  • Unlimited local checks, readiness score and blockers
  • Provider cards with live checks through MCP
  • Codex, Claude Code and Gemini CLI
  • 2 full checks with a free account, 6 core areas
  • Runs on your machine, MIT

Pro

$9.99 per month

Full checks from the Studio. Choose Run full check, confirm what gets sent, and get findings for every production area.

  • 50 full checks a month from the Studio
  • All production areas checked
  • Everything in the free Studio
  • Billed monthly, cancel any time

Full pricing and terms

preflight · your-app 8 checks

Preflight for your stack

  1. Row level security on every table rls_disabled
  2. Service role key kept off the client service_role_key_in_client_code
  3. Pooler port for serverless pooler_port_mismatch
  4. Webhook handler for payments missing_stripe_webhook
  5. .env and secret files gitignored secrets_in_repo
  6. Every env var in.env.example env_var_drift
  7. Rate limits on public routes missing_rate_limit
  8. Error monitoring wired in missing_monitoring

Vercel, GitHub detected, each with its own card in Studio.

02Run it in your app folder

npx -y viberaven

Works withClaude CodeCodexCursor