What does this skill do?

The Skill Production Audit determines whether an application is ready for production deployment by identifying what could go wrong, what still needs to be fixed, and whether it is safe to launch. It inspects critical areas such as APIs, authentication, payments, webhooks, and migrations; applies risk assessments to security, data, and operations; and generates a score from 0 to 100, highlighting blockers and specific next steps.

Public Pre-Launch
Before a customer deployment or demo, verify that there are no critical blockers along the production path.
Post-fusion follow-up
After merging a new feature, assess the risks it introduces before opening a release pull request.
Security and Data Audit
Verify that the authorization policies are applied on the server and that no secrets are exposed on the client.
CI Assessment and Rollback
Verify that the CI is green, that migrations are secure, and that there is a documented rollback plan.

Usage examples

🚀 Direct Launch Inquiry
Is this ready to go into production?
🔀 Release branch review
Check out the release/v2.0 branch and let me know what would break in production if we deployed it now.
🔒 Security Verification
Audit the authentication and payment limits of the local repository before deployment.
📊 Readiness Score
Please provide me with the production readiness score for this PR and list the blockers.

Features

Objective score 0–100 Assigns a score based on local evidence, forcing the prioritization of blockers and improvements.
Critical Limit Inspection Examine API routes, authentication, data, payments, webhooks, background jobs, and deployment settings.
Multidimensional Risk Lenses It systematically evaluates security, data integrity, payments, operations, and user experience.
ID Verification and Infrastructure Check CI workflows, tests, database migrations, environment variables, and the existence of a rollback plan.
100% local and privately owned It does not send data to external services: the entire audit is based on evidence from the local repository.

Frequently asked questions

No. The skill works exclusively with local data from the repository: Git commands, files, migrations, and CI configurations. It does not send data to external services.
The score is capped at 69 if the webhooks are not idempotent, if there are no authentication mechanisms for sensitive data, if the migrations are not secure, or if there is no rollback path.
Yes. The skill checks for common production patterns (API, authentication, payments, migrations, CI) regardless of the language or framework, although it works best with projects that use a Git repository.
A 0–100 score indicating the level of risk, a list of roadblocks, high-value improvements, reviewed evidence, missing evidence, and a specific next step.
Production Audit — Is Your App Ready to Go Live?

¿Prefieres escuchar el contenido? Genera la narración de audio con un clic.