
Preflight - Launch security checks for AI-built SaaS apps
为GitHub仓库运行安全审计,检测密钥泄露、认证问题和部署漏洞。
@emanueldev4 · X
Building Preflight a simple way to catch issues before your website goes live.
完整作品展
技术栈
60 projects

为GitHub仓库运行安全审计,检测密钥泄露、认证问题和部署漏洞。
@emanueldev4 · X
Building Preflight a simple way to catch issues before your website goes live.


Chrome扩展,在粘贴到AI工具前拦截您的API密钥和密码。
@Secureintent_ai · X
SecureIntent is a free Chrome extension that intercepts API keys, tokens, and passwords before you accidentally paste them into AI tools

使用硬件认证和OTP保护GitHub拉取请求。
jallmann · HN
> want without a PR process that requires hardware authentication or proof of presence Just curious, what do you use for this? I built OTP Guard [1] a few years ago for exactly this problem, although I haven't seen any alternatives in the space. Does GitHub have something built-in now? The original framing was more "local malware compromising your GitHub account" ... it never occurred to me that the malware could be a LLM. I really should update the page. [1] https://otpguard.com

扫描GitHub代码库查找安全漏洞,AI提供修复建议。
u/uwais_ish · Reddit
Three weeks to build an AI security scanner. The scanner was the easy part. Shipped RedFlag this month. Breakdown of where the time actually went, because it was nothing like I estimated. Stack: Next.js 16, Auth.js v5, MongoDB, Stripe, OpenAI. Deployed on Vercel. What I thought would be hard: getting an LLM to find real vulnerabilities. What was actually hard: getting it to stop finding fake ones. First working version flagged 200+ issues on a clean repo. Every one plausible, most of th

扫描 GitHub 仓库检查生产就绪度、安全性和可扩展性。
@nathanghart · X
Submitting for approval. I built a free tool for anyone about to ship a vibecoded app. It scans your repo for what bites you in prod (leaked keys, no auth, no error handling). I ran it on 1,868 AI-built apps and even caught my own scanner being ~42% wrong.

用 7 个扫描器扫描 Web 应用漏洞,获取 AI 修复建议和 PDF 报告。
@hexorasec · X
Paid Hexora accounts now get PDF security reports. Every finding with evidence, CVSS scores, remediation steps, and AI fix prompts, in a report you can hand to a client or keep for compliance. Live for Starter, Pro, and Max. #buildinpublic #vibecoding

ARGUS:为AI代理流程的可观测性平台,检测故障并解释根本原因。
@VaraadDurgaay · X
Solving the prb of observability in ai agents

监控应用依赖的 75+ 外部服务,故障时获得即时告警。
@DownDrHQ · X
DownDr — Otto watches 75+ services your app depends on and tells you when it's them, not you. MRR: a proud $0, launched days ago 😄 Why: everyone who's ever debugged a bug that turned out to be someone else's outage is the market. 🦦

一个提供认证、存储和LLM集成的Backend平台,无需服务器或配置。
ent101 · HN
The Safe, Production-Ready Backend for AI-Generated Apps

CanaryHub 实时监控应用和 API,故障时通过 Telegram 即时警报。
u/AgitatedLemon6836 · Reddit
I've got too many sites to monitor at this point I have been working on a bunch of different SAAS ideas at this point, some of them are just parked right now as I have decided to market others or have lost passion for the project. Its hard to check logs in a unified fashion for a bunch of different sites, I have backend's on Fly io, Heroku, Vercel, Hetzner and AWS (for varying reasons, some consulting, some work etc). just wanted like text message updates for things with a summary, like "3
