Project overview
Seaworthy performs a static, no-network scan before deployment for common security mistakes in AI-built web apps, including exposed secrets, missing row-level security, unauthorized mutations, risky CORS, debug mode, open admin routes, and writable storage. It returns a ship-or-do-not-deploy decision with file-level findings; it is not a penetration test and primarily targets Next.js and Supabase scenarios.
Repository facts
- Primary language
- Shell
- License
- MIT
- Repository updated
- Jun 22, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacyDevOps and deployment
Platforms
Claude Code, Codex, and more
Capabilities
Verification and evals
Audience
General users