VibeRaven Guides
Barındırılan, salt okunur, oturum açma gerektirmez (https://viberaven.dev/mcp). VibeRaven bulma kimliklerini açıklar ve Vercel + Supabase uygulamaları için başlatma rehberleri ve kontrol listeleri döndürür. Deponuzu asla okumaz.
Barındırılan MCP Sunucusu
npx add-mcp 'https://viberaven.dev/mcp'Claude Code, Codex, Cursor ve daha fazlasına kurulur
Dokümantasyon
repo
github.com/you/your-app
DetectedReady
web
your-app.vercel.app
Env vars documentedReady
payments
Stripe
Webhook handler foundReady
auth
Auth.js
Auth secret setReady
database
public.posts
RLS on · owner policiesReady
monitoring
Sentry
Errors trackedReady
Services
cacheemail
Sample app. Finding ids are real VibeRaven checks.
your-app
No blockers found
npx -y viberaven
Sample stack. Checks and detections are real VibeRaven output.
-
Finds your stack
Reads the repo and names every service the app runs on. -
Checks each piece
Row level security, webhooks, secrets, env vars, rate limits and monitoring. -
Hands the fix to your agent
A task list for Claude Code, Codex or Cursor to work through.
Anyone anon key
id user_id body created_at
rls_disabled · critical Anyone holding the anon key your frontend ships can read and change these rows.
75 score · 1 blocker
01It reads the repo and flags a table anyone can read.
viberaven check
viberaven check · ~/posts-app
No RLS policy proof in migrations (rls_disabled)
1 public table without row level security: public.posts (supabase/migrations/0001_posts.sql:1). Anyone holding the anon key your frontend ships can read and change those rows through the Data API.
No error monitoring detected (missing_monitoring)
No Sentry/PostHog (or similar) instrumentation was found. Production errors will only surface when users complain.
Verdict: 1 blocker, 0 warnings · score 75
Fix: viberaven fix · Details: ~/posts-app/.viberaven/agent-tasklist.md
Step 1 of 3: Scan. It reads the repo and flags a table anyone can read.
Output captured with viberaven 1.6.1. We wrote the migration by hand for this demo.
-
Open tables
Supabase tables with no row level security.rls_disabled -
Exposed keys
Secret files not gitignored. The service role key in client env or code.secrets_in_reposervice_role_key_in_client_envservice_role_key_in_client_code -
Unsigned sessions
Auth.js with no auth secret referenced.auth_secret_missing -
Silent payments
Stripe with no webhook handler.missing_stripe_webhook -
Missing env vars
Vars your code reads that.env.example lacks.env_var_drift -
No guard rails
No rate limits. No error monitoring.missing_rate_limitmissing_monitoring
Studio
$0 open source
The local Studio on your machine. Every local check, every provider card, your own coding agent. No account needed.
- Unlimited local checks, readiness score and blockers
- Provider cards with live checks through MCP
- Codex, Claude Code and Gemini CLI
- 2 full checks with a free account, 6 core areas
- Runs on your machine, MIT
Pro
$9.99 per month
Full checks from the Studio. Choose Run full check, confirm what gets sent, and get findings for every production area.
- 50 full checks a month from the Studio
- All production areas checked
- Everything in the free Studio
- Billed monthly, cancel any time
preflight · your-app 8 checks
Preflight for your stack
- Row level security on every table
rls_disabled - Service role key kept off the client
service_role_key_in_client_code - Pooler port for serverless
pooler_port_mismatch - Webhook handler for payments
missing_stripe_webhook - .env and secret files gitignored
secrets_in_repo - Every env var in.env.example
env_var_drift - Rate limits on public routes
missing_rate_limit - Error monitoring wired in
missing_monitoring
Vercel, GitHub detected, each with its own card in Studio.
02Run it in your app folder
npx -y viberaven
Works withClaude CodeCodexCursor