Production Audit
Ship-or-block audits for Muse: local-evidence production readiness reviews with risk lenses, scored 0-100, no repo data sent to external services.
- What
- Ship-or-block audits for Muse: local-evidence production readiness reviews with risk lenses, scored 0-100, no repo data sent to external services.
- Cost
- Free
- Needs
- Use "Production Audit" with your Muse.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor: a production readiness audit that answers "is this ready to ship?" from local evidence, without uploading your repo to an external audit service. Builds the audit from evidence you authorize: release surface, recent changes and branch state, runtime and auth and payment and deployment boundaries in the repo, CI and tests and migrations and rollback paths. Applies five risk lenses: security and auth (route separation, server-side enforcement, secrets out of bundles, rate limits, prompt injection defenses), data integrity (forward-clean migrations with rollback plans, staged backfills, idempotent retries), payments and webhooks (signature verification, idempotent fulfillment, replay and duplicate handling, test versus live credentials), operations (clean-checkout startup, validated env vars, health checks, documented deploy and rollback paths, useful logs without secret leaks), and user experience (launch-critical paths on desktop and mobile, loading and error states, recovery paths). Scores 0-100 in four bands (Blocked, Risky, Launchable With Caveats, Strong) with hard caps: auth missing on sensitive data or non-idempotent payment webhooks or exposed secrets or no rollback path caps the score at 69, non-green CI caps it at 84. Output leads with one sentence (score, band, top risks), then blockers, high-value fixes, evidence checked, evidence missing, and one next action. Use before a launch, after a merge, or when asked what breaks in prod. By @affaan-m, listed here with credit to its creator. From the affaan-m/ECC repository (MIT). Honest caveats: engineering triage, not a formal compliance, legal, financial or medical certification; needs a real repo, CI, or deployment surface to work from, ideas alone are not enough; green CI is not production readiness. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Copy the install package below, then paste it into MuseThe install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?
Use "Production Audit" with your Muse. Prerequisites: none to install. Pure guidance; a repo, release branch, or deployed URL to audit helps. 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/production-audit/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Audit this for production readiness: [repo path, branch, or deployed URL]." 3. Ask it to gather local evidence first (git state, CI, migrations, env docs), then score 0-100 with blockers and one next action. Tip: run it after every merge to main during launch week; treat the score as a prioritization tool, not a grade. Safety: a skill is plain-text instructions; it runs nothing by itself. Keep secrets out of the evidence you share.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.