$ coprompt scan https://linkbase.app --tier 0GET https://linkbase.app 200 1.2sstack · Supabase · Vercel · Resend detectedfetching client bundle … 2.4 MBrunning 30 checks …■ critical anon key exposed — public.users readable (1,284 rows)■ critical service_role key in client bundle · main.js:1◆ high preview deploy shares prod database (312 rows)◆ high /api/admin reachable without authauth policies …public.users RLS OFFpublic.orders RLS OFFpublic.messages RLS OFF▲ medium missing headers ×3 — CSP · HSTS · X-Frame▲ medium CORS allows * on api.linkbase.app▲ medium .env.local committed 4 commits agostorage bucket "avatars" … public-readJWT secret entropy … weak (guessable)rate limiting … none on /auth/loginsecrets scan … 2 live keys found› STRIPE_SECRET_KEY sk_live_… active› RESEND_API_KEY re_… activedependency audit … 3 high · 7 moderateagent trace … tool calls unsandboxedprompt-injection surface … 4 inputs unescapedclient routes … 6 pages leak internal idsemail DNS … SPF ok · DMARC missing30 scanners · 13 findings · 2 critical · 2 high · 4 mediumexposure … 1,596 records readable without authreport ready → coprompt.dev/r/8a31c9$ _
Finds what your coding agent missed — before someone else does.
Used by customers of