Nothing to hand? Load the — an Express router with the classic pre-deploy sins — or the , where the queries are fine and the problems are narrower.
Paste the code
An endpoint, a module, a diff, a config, or all of it. The instant prescan reads it for free while you type and lists what it mechanically found: hardcoded secrets, SQL built by concatenation, unsafe HTML sinks, tokens in localStorage, logged secrets, verbose errors, weak hashes, debug mode, plus the endpoints and attack-surface signals in your paste.
The AI reviews it
A ship/fix-first/block verdict; severity-ranked findings, each quoting the code it concerns and carrying corrected code; a twelve-item pre-deploy checklist scored pass, fail or not-observable against your paste; and an honest health check across secrets, injection, auth, browser exposure and operations. Every prescan hit is confirmed or explicitly set aside — including the false positives.
Take the rewrite and go
Your own code hardened — same functions, same intent, findings fixed — as a downloadable file, or loaded straight back into the form as the new paste. Then fix and re-review: every run is compared against the one before it, so you see the verdict move, which findings are gone, which are new, and which checklist items flipped. Review history follows your account when you are signed in, plus ordered next steps, findings as CSV, and Markdown or JSON export.
Derived from the @affaan-m/security-review skill (MIT license).