Public response checks for security headers and deployment posture.
- CSP / HSTS notes
- cookie flags when visible
- CORS warning signs
A $5 authorized, non-invasive quickcheck for AI-built apps. Send one public URL or dependency manifest you own; receive a short posture note and a paste-ready agent rule for security-sensitive edits.
What gets checked
This is not a penetration test or compliance certification. It is a first-pass posture check for founders using AI agents to ship public apps faster than their review process can keep up.
Public response checks for security headers and deployment posture.
Manifest review for stale package pins and security lookup gaps.
Obvious client-side leakage and boundary reminders.
Delivery
After checkout, send the public URL or manifest and the sentence "I own or am authorized to assess this target." Private repos can send manifests only.
The check is defensive and non-invasive. If a buyer needs deeper testing, the next step is a properly scoped authorization brief before any active assessment.
1. Send $5 in USDC or MATIC (Polygon) to:
0x5E3453A118BA479160895A4285EF0f8b8955F87C
2. DM the tx hash + your target URL/manifest on X:
DM @ASmith1683525 on X