Skip to content
Supreme Pack

A skill for Claude Code and Codex · Software and infrastructure

Before you ship to production, the checklist that holds the release back.

security-checklist is the skill that has your AI audit a SaaS's security before launch or after a sensitive change, covering authentication, authorization, validation, uploads, payments, webhooks, headers, SSRF, supply chain, and logging. It has a release gate that stops the release whenever a critical item fails, and a rule that only approves what has evidence behind it.

Buy R$ 57 R$ 57 one time payment

Solo skill: unlocks right away, no guarantee after download. Purchase terms.

Or get all 25 skills plus 9 bonuses in the Supreme Pack for R$ 497.

The problem

Asking AI to review security isn't the same as auditing it.

A security audit done by AI with no process turns into a generic list of best practices, ends up approving things just by reading, and nobody actually tests anything for real. Three symptoms, and what changes with the skill.

What the work looks like without security-checklist and with it
Without the skillWith security-checklist
The AI reads the code and declares it secure, without knowing where authentication lives, how each customer's data is kept separate, or where payments actually flow through.A real map of the system first, with routes, tenant isolation, payment flow, and where the secrets live, and only then the checklist run against that map.
The finding shows up vague, something like this might be vulnerable, with no file, no line, and no way to reproduce it, so nobody can check it without reading the entire project.Every finding ships with a file, a line, and a concrete exploitation path, and whatever can only be proven by running stays on a separate list, never marked ok just because someone read it.
Nobody tested swapping one user's id for another's, the webhook doesn't validate its signature, and nobody searched the repository's history for leaked secrets.Unauthorized-access testing on every endpoint that takes an identifier, webhook signature and deduplication checked, and deterministic tooling added on top of the AI's judgment.

What you get out of it

What you get out of it.

A security report you can verify without reading the entire codebase, with a clear go or no-go decision.

  • 01

    System map

    routes, authentication, tenant isolation, payments, and secrets

  • 02

    Findings with evidence

    severity, file, line, and a reproducible exploit for every issue

  • 03

    Code versus runtime

    what was confirmed by reading, and what still needs a live test

  • 04

    Release verdict

    approved, approved with reservations, or rejected, decided by the release gate

How it works

You ask for the review. It asks for the system map.

  1. Maps before checking

    Public, authenticated, admin, internal, and webhook routes, where authentication is enforced, how each customer's data stays separate, and where the secrets live.

  2. Separates code from runtime

    Every item gets tagged as verifiable by reading, only by running, or both. The AI only states a result for what it can prove by reading, and always with evidence.

  3. Classifies every finding

    Blocker, high, medium, or low, with a file, a line, and a concrete exploit, from a login bypass to a missing header.

  4. Tests what needs testing

    Unauthorized access on every endpoint with an identifier, both reads and writes, plus a secrets scan, a dependency audit, and static analysis added to the AI's own judgment.

  5. Decides through the gate

    An exposed secret, broken authorization, a payment with no idempotency, or a webhook with no signature all stop the release. With zero blockers open, it ships.

Before you buy

What you need, and what it never does.

What you need nothing extra to pay for

  • Claude Code or Codex, either one works
  • The SaaS's repository and a test environment for the runtime items
  • Free secrets and dependency tools, like gitleaks and npm audit

Running the same audit in both Claude Code and Codex and cross-checking the two reports boosts confidence, and the skill explains how to do it.

Setup zero

  • Drop the folder into your Claude Code or Codex skills location
  • Before shipping to production or after a sensitive change, it kicks in on its own
  • Fill in the header with project, environment, and scope, and it starts with the map

What it never does by rule

  • Mark as secure an item that can only be proven by running it
  • Accept a finding with no file, line, or exploitation path
  • Say it tested something when it only read the code
  • Approve a release with an open blocker
  • Swap a deterministic tool for the AI's opinion

Its limits

It audits and flags. It's not a substitute for a pentest.

The checklist covers what a SaaS needs before going to production, but approved by reading isn't the same as secure: whatever depends on a live test stays logged as an explicit pending item until someone actually runs it.

For a product handling highly sensitive data, real money, or a client requirement, a human pentest still makes sense, and the skill leaves the ground organized so that pentest goes further.

LGPD (Brazil's data protection law), with legal basis, retention, and data subject rights, belongs to lgpd-baseline, and the automated test suite to testes-automatizados-expert, both in the catalog.

What you receive

One folder. Drop it in and audit.

  • The entire skill, ready to install in Claude Code and Codex
  • The complete checklist for auth, authorization, validation, uploads, payments, webhooks, headers, SSRF, supply chain, and logging
  • How to test each area and the weaknesses that show up most often in it
  • Two-source audit process and the evidence template
  • Install guide and version history
  • 12 months of updates, with a notice in your Supreme Pack area for every new version
  • Files4
  • Size22 KB
  • Version1.0.0
  • LanguagePT-BR
  • Updates12 months
  • Pack guarantee7 days

The price

Just this one, or all of them.

Just security-checklist

R$57one time payment

  • The full skill, ready to install
  • 12 months of updates for it, announced in your account
  • Pix or card, unlocked right away
  • No guarantee after download (see terms)
Buy the skill

Bought it solo and now want it all? Message me on WhatsApp and I will deduct what you already paid.

Supreme Pack

R$ 1.665R$497or 10x on a card

  • This one plus the other 24, across five areas
  • 9 bonuses I do not sell separately
  • Any new skills I release over the next 12 months
  • 12 months of updates for all of them
  • A 7 day guarantee on the pack
Get them all for R$ 497

Buying all 25 solo adds up to R$ 1.665. The pack pays for itself by the ninth skill. See everything the Supreme Pack includes

04 · Software and infrastructure

More from software and infrastructure.

Before you ask

Questions about security-checklist.

What does security-checklist cover?

Authentication, authorization and tenant isolation, input validation, uploads, the financial flow, webhooks, headers and CORS, SSRF, dependencies, and logging, with a release gate that stops the release whenever a critical item fails.

Does it replace a pentest?

No. It runs the pre-production audit with evidence and separates out whatever needs a live test. For highly sensitive data or a contractual requirement, a human pentest still applies.

Do I need to know how to code to use it?

Not to run it, but it helps to understand the findings. That's why every issue comes with a file, a line, and a concrete exploit: you can verify it by opening the file at that exact line, without reading the whole project.

Does it use tools beyond the AI itself?

Yes. Secrets scanning through the history, dependency auditing, and static analysis where possible, because a deterministic tool catches the committed secret the AI might miss, and the AI catches the broken business logic the tool can't.

Can I use it to audit a client's project?

Yes, with the client's authorization for the scope being tested. The license covers your work for other people; what's off limits is reselling or redistributing the skill.

Finding it before launch costs a lot less.

One-time payment, 12 months of updates. No refunds after download; the Supreme Pack comes with a 7-day guarantee.

Get the skill for R$ 57 Pix or card · shows up in your account right away