Home/Playbooks/Harden Before Ship
Ends in commits Playbook · 5 briefs

Harden Before Ship

Lock the doors before you ship — then ship the fixes as commits.

Free & open · no signup · audits are read-only — the Fixer asks before any edit · nothing leaves your machine

Why this sequence

The security pass before you expose anything: secrets, access control, injection paths, and an attacker's-eye threat model — then the Fixer turns the findings into verified commits.

The map

Run it in order

The conductor fetches each brief in turn and writes its report before moving on — later briefs can build on earlier findings. Or copy any single stage to run it alone.

what you'll have at the end

5 reports in reports/, plus the run's own INDEX.md: SECRETS.md, ACCESS.md, INJECTION.md, THREATS.md, FIXLOG.md. Feed them to the optional Studio to turn findings into commits, or run 28 · Roadmap Synthesis to merge them into one plan.

Get started

One paste runs the whole thing

Copy the conductor into your agent inside the repo you want checked. It runs each Goal Prompt in sequence, honoring each one's ask-first rule.

View raw ↗
In this playbook

The 5 briefs