Everything to check before a repo goes public.
Free & open · no signup · read-only — every stage ends by asking · nothing leaves your machine
Before the repo goes public: safe to expose, dependencies sound, and every license accounted for.
The conductor fetches each brief in turn and writes its report before moving on — later briefs can build on earlier findings. Or copy any single stage to run it alone.
3 reports in reports/, plus the run's own INDEX.md: SECURITY-AUDIT.md, DEPS.md, LICENSES.md. Feed them to the optional Studio to turn findings into commits, or run 28 · Roadmap Synthesis to merge them into one plan.
Copy the conductor into your agent inside the repo you want checked. It runs each Goal Prompt in sequence, honoring each one's ask-first rule.
A defensive review of your own codebase — auth gaps, injection surfaces, exposed secrets, and data leaks, ranked by exploitability.
Vulnerable, abandoned, oversized, or duplicated packages — the full health check on every dependency this project stands on, with removal candidates named.
Every dependency's license, the ones incompatible with how you ship, the attribution you owe, and the copyleft reaching into your own source.