Public repo checklist
AI App Launch Safety Checklist for Public Repos
A practical pre-launch pass for AI-built apps, agent workflows, and MCP projects.
No credentials are needed. This is not a certified pentest.
Optional next step
Did this checklist save you time?
If the checklist helped you catch a launch issue or make a repo safer, optional
support helps fund more public proof-of-work, checklists, triage notes, and mini-audits.
If you want a scoped review instead, start with a public fit check.
Donations are optional thanks for public work. They do not create an audit slot,
support obligation, or guaranteed deliverable. Paid audits require fit and scope
confirmation first. Do not send secrets, private keys, tokens, customer data, or account access.
When to request
Ask for a review when launch risk matters more than speed.
Good fits handle auth, payments, user data, APIs, webhooks, MCP tools, or agent workflows.
Send a public repo URL and launch context only. Do not send secrets or account access.
Fit checks and paid audits start with public-safe scope confirmation. Do not include
secrets, private repo contents, customer data, or account access.