1Which app?
One target per app. Paste a URL to add one.2What this audit will do
SRCCode tells
Scans a project folder on this computer. Never edits it.HPast runs
Every GUI and command-line run is saved in the reports folder.How to read a result
Read-only vs. write tests
Everything in this app is read-only: it asks your site and your Supabase project the same questions any visitor's browser could ask. That's why it's safe on production.
Write tests go one step further and prove whether a stranger could change data (UPDATE/DELETE, and INSERT if you give it a test row). They only run from Terminal, and only if all four gates pass: the target allows it, the environment isn't production, you add --destructive, and you type the target's name to confirm. By default they're built to change zero rows. SAFETY.md has the details.
node lockright.mjs run targets/my-app-staging.target.json --destructive
Words you'll see
From Terminal, if you ever want it
node lockright.mjs scan https://my-app.com # audit from just a URL node lockright.mjs init my-app --url https://my-app.com # save it as a target node lockright.mjs run targets/my-app.target.json # read-only audit node lockright.mjs run targets/my-app.target.json --fail-on high # for CI: exit 2 on High or worse node lockright.mjs schedule targets/my-app.target.json --weekly # weekly re-check (macOS) node lockright.mjs mcp # MCP server for AI editors node lockright.mjs scan-tells ~/Documents/GitHub/my-app node lockright.mjs license # how this computer is licensed node lockright.mjs list-checks