product image

Ship It, Don't Leak It

$23.75$19Save 20%

The pre-launch security playbook for AI-built apps

Your AI-built app works. The question is who else can use it.

An August 2026 scan of 30,998 live apps built with Lovable, Bolt, v0, Replit and Base44 found 57% of Supabase-backed apps let a stranger read database tables without logging in. One in 23 shipped a secret key in public code.

Ship It, Don’t Leak It is the pre-launch security playbook for apps built with Lovable, Bolt, Cursor, Claude Code and Codex: the checks and fixes that stop the leaks AI-built apps actually have, plus scripts that run the checks for you.

Inside (59-page PDF):
• Why AI-built apps leak, with real 2026 incidents
• The Attacker’s Hour: audit your app like a scanner in ~60 minutes
• Secrets: env vars, git history, build output, MCP configs
• Supabase RLS done right, with copy-paste policies
• Access control: IDOR, auth checks, server actions, Stripe webhooks
• Slopsquatting and dependency patching
• AI features: prompt injection, cost abuse, leaky RAG
• Securing Claude Code, Codex, Cursor and MCP
• Using AI as your security reviewer
• Launch gate, monitoring and incident runbook

Bonus files (tested, no dependencies): leakcheck.mjs secret scanner · rls-probe.mjs · rls-policies.sql · security reviewer Agent Skill + rules for CLAUDE.md/AGENTS.md/Cursor · Claude Code guardrails hook · GitHub security workflow + gitleaks config · 40-point launch checklist, incident runbook, audit report template

Verified 14 September 2026, with sources. By Herdoy Almamun, full-stack developer (9 years).

Frequently asked questions