AI Build Sanity Check
$13Catch mocks, placeholders, swallowed errors, and fake-success endpoints before an AI-built app reaches users.
184 focused agent skills that read the open SKILL.md standard. Free repo utilities through security, model resilience, dev and DevOps, sales, and creator tools. Each does one job you can name.
184 skills
Browse them for ideas, or explore the full catalog by the job you need. Every listing includes a sample, declared permissions, and known limits.
Catch mocks, placeholders, swallowed errors, and fake-success endpoints before an AI-built app reaches users.
Find commented-out dead code across eight languages, preserve important notes, and preview every removal before writing.
Scan schemas, seed data, configuration, and logs for personal data before it leaks, without exposing the values it finds.
Turn CRM exports or live CRM data into a 12-month forecast with scenarios, win-loss themes, and executive-ready reporting.
Skillstore reviewed the exact pinned file sets behind these free skills and labels each reviewed version Safe. Its reports are evidence, not a guarantee; the matching detail page shows the caveats and the paid next step.
Check crawl-control files locally. The report found no confirmed security findings across the reviewed package.
Start free & inspect the audit →Generate documentation from repository evidence. Its two local-help-command capability items remain visible.
Start free & inspect the audit →Draft Conventional Commits from staged changes. The report treats command detections as legitimate Git workflow instructions.
Start free & inspect the audit →Diagnose local setup failures without exposing environment values. The review confirms its local-only and approval-before-stop boundaries.
Start free & inspect the audit →Start here. No account, no charge. Read-only or preview-before-write.
Return the single best-supported detail that deserves one more question, with benign and concerning explanations.
Tie one normalized marketplace payout summary to the cent and name the unexplained difference without connecting an account.
Check one ACR record for date, version, scope, manual testing, release drift, and retest gaps without claiming conformance.
Check one structured RFP addendum register for missing acknowledgments, deadline conflicts, and a stale response revision.
Calculate one supplied renewal notice deadline and produce a calendar-ready owner card without interpreting or sending a contract notice.
Inspect a real Gumroad cover and thumbnail pair, render safe-zone previews, and get PASS, REVIEW, or REWORK findings before upload.
Classify one redacted GitHub Actions failure and get cited evidence plus three bounded next checks before changing workflow code.
Fix the "it works on my machine" problem before you touch the code.
Turn a .env into a safe .env.example you can commit. Keeps every key, strips every value, preserves comments and order, and flags the secret-looking keys.
Generate Conventional Commit messages from your staged git diff.
Turn a company URL or name into a B2B lead profile.
Generate a ready-to-use LICENSE file for your repo. Pick from MIT, Apache-2.0, GPL-3.0, MPL-2.0, BSD-2-Clause, BSD-3-Clause, or The Unlicense, fill in your name and year, and get the canonical text.
Align messy Markdown tables so the source is readable, or build a clean table from pasted CSV. Changes spacing only, never the cell content.
Turn a lead profile and a trigger event into a cold email worth sending.
Turn a messy CRM CSV export into a clean sales pipeline report.
Generate a README from your actual repo, not a hallucinated guess.
Check your robots.txt and sitemap.xml for the mistakes that quietly block crawlers, and never touch the live site.
List every TODO, FIXME, HACK, XXX, BUG, and OPTIMIZE comment in your codebase with file, line, and tag, grouped with counts. A clean tech-debt inventory instead of scrolling grep output.
For the files, contracts, and failure modes your AI assistant actually touches.
Separate observed mutuality and curiosity from inconsistency, intensity, projection, and insufficient evidence without compatibility scores or diagnosis.
Test whether a response is proportionate, protective, principled, symbolic, retaliatory, status-driven, or insufficiently supported.
Scan supplied context for overlooked vulnerable people, practical needs, overload, exclusion, and preventable harm without gender stereotypes.
Separate information gaps from authority, emotional, safety, and consequence reasons for human takeover, then prepare a compact handoff packet.
Make a subagent complete the bounded assignment, preserve shared state, and refuse unsolicited expansion or external authority.
Make an agent inspect neglected material for overlooked value, provenance, reusable components, and unresolved clues without inventing worth.
Make an agent herd wandering work into explicit outcomes, owners, dependencies, boundaries, and the next executable move.
Make an agent notice missing sources, weak attribution, unsupported certainty, and information disorder while correcting calmly.
Map who may be affected, how consequences may spread, and which safer alternatives reduce permanence, exposure, or coercion.
Classify a consequential people-facing action as suitable for automation, revision, delay, human review, human delivery, or no automation.
Audit release consistency, discovery surfaces, supported claims, evidence freshness, and Product Hunt or Show HN readiness before distributing an agent product.
Reconcile provider bills, usage events, model prices, retries, and customer allocation into deterministic AI cost findings.
Check normalized iCalendar events for floating times, DATE mismatches, missing boundaries, sequence errors, and recurrence evidence.
Find likely emailed receipts, separate them from invoices and non-receipts, deduplicate, review, forward, file monthly, and reconcile every outcome.
Test an AI or rules-based resume screener for outcome changes, score drift, missing evidence, sensitive-term leakage, and human-review gaps.
Audit real RAG evidence traces for missing expected sources, impossible citations, unsupported claims, stale evidence, unused context, and weak routing.
Replay automation traces against explicit rules for required steps, order, retries, approvals, idempotency, external side effects, duration, and terminal success.
Penetration-test your coding agent's guardrails before you ship.
Scaffold and audit secure MCP servers with input schemas, confirmation gates, and safety-first tool definitions.
Stop your agent from claiming done before it is proven.
Find the model-version coupling that breaks when you move to a new model: hardcoded names, renamed parameters, token-limit assumptions, response-format and tool-schema coupling, and hardcoded cost constants.
Before an agent acts on a plan, verify that the things it named actually exist.
Scan a SKILL.md package for prompt injection and secret exfiltration before you install or publish an agent skill. Most malicious instructions hide in the natural-language prose, not the code.
Drive a browser from your agent without the token bloat.
Inventory every LLM model and provider your code depends on, the AI bill of materials, and flag the concentration risk. When a model can be pulled offline overnight, you cannot manage a risk you cannot see.
Lint your AGENTS.md, the cross-tool standard for agent instructions, for the problems that make a coding agent misbehave. Also works on CLAUDE.md and .cursorrules.
Flag the destructive operations in a shell command or script before anyone runs it.
Find the LLM calls that break when a model blocks a response or falls back to another model.
Find the code that quietly runs up your LLM bill.
Generate an llms.txt for your site and validate an existing one against the spec. llms.txt is the emerging standard for telling models and agents which parts of your site to read.
Pull the real commitments out of a meeting transcript, with owners, and separate firm action items from tentative let-us-revisit ones. It never invents an owner.
Find the LLM integration code that will not survive a provider being pulled or going down. This is about the model disappearing, not the model declining a request.
Generate the model and vendor risk register a security lead asks for the morning after a model gets switched off. Built from your real dependencies, focused on availability and continuity.
Scan your OpenClaw config for the settings that quietly hand your agent too much power.
Lint a prompt template for the issues that cause injection and flaky output. It detects problems; it does not write prompts.
Audit Agensi skill packages for marketplace readiness, formatting compliance, and safety pre-checks.
Lint the function-calling tool definitions your agent exposes, so it picks the right tool instead of the wrong one or none.
Catch the mistakes that leak data or let an agent off its leash.
Gate a release on consistent SBOM, VEX, identifier, relationship, and artifact-digest evidence.
Validate supplied MCP OAuth metadata and transcripts for discovery, audience, scopes, PKCE, challenges, and token hazards.
Reconcile deletion-request evidence across systems, subprocessors, retention exceptions, and backup replay before human review.
Reconcile owner-defined AI transparency scope with labels, notices, technical markings, and release claims.
Track an owner-confirmed CRA reporting workflow through its 24-hour, 72-hour, and final-report evidence stages without deciding reportability.
Reconcile employee exits and role changes with IdP, SaaS, exception, and revocation evidence before an access closeout is accepted.
Check whether accessibility conformance claims still trace to current, scoped, version-matched, manually reviewed, and retested evidence.
Verify a final PDF or DOCX for named sensitive terms, hidden text, metadata, comments, revisions, attachments, forms, and embedded content before owner release.
Compare incoming security questionnaire answers with an approved library for stale evidence, scope mismatch, dropped citations, and material wording drift.
Diagnose why Stripe Checkout, the Billing Portal, or your webhooks are not working.
Vet dependency changes for supply-chain risk before you install, commit, or release.
Audit Supabase for the row-level-security mistakes that quietly expose data.
Scan your schemas, seed data, config, and logs for personal data before it leaks.
Check an AI-built app for work that looks finished but is not.
Audit a Helm chart for insecure defaults before you deploy to Kubernetes.
Check your app for the security mistakes that leak data before you launch, explained in plain English. Built for the non-technical founder shipping an AI-built app, every finding tells you what is wrong, why it matters, and how to fix it.
Check your app, site, and ad copy for the AI disclosures US regulators and ad platforms now expect.
Audit your SPF, DKIM, and DMARC records for the misconfigurations that get mail rejected or sent to spam. Paste a DNS zone file or dig output.
Catch the dangerous migration before it locks or wrecks your production database.
The checks and generators that keep a codebase and a pipeline honest.
Turn an app inventory into a local watch plan for user journeys, jobs, webhooks, integrations, alerts, ownership, freshness, and recovery.
Find direction, logical-CSS, interpolation, icon-mirroring, and render-evidence gaps before an RTL release.
Flag reserved names, invalid characters, trailing dots, case collisions, Unicode normalization collisions, and path-length risks.
Catch missing legacy URLs, duplicate sources, self-redirects, chains, and loops before a site migration.
Review an npm pack file list for missing runtime output, sensitive files, and payload drift before publish.
Check supplied repository paths and ignore patterns for uncovered or already tracked sensitive-looking files.
Reconcile Android target API, developer verification, app registration, signing identity, distribution scope, extension, and console evidence.
Reconcile SDK, required-reason API, data-use, privacy-manifest, and questionnaire evidence before an App Store release.
Audit restore-test evidence against declared RPO, RTO, recency, environment, dependency, smoke-check, and evidence requirements.
Compare two XLSX versions for formulas replaced by values, formula-family drift, broken references, new cycles, and workbook-control changes.
Find and finish the UI states AI-built apps commonly miss, then verify the smallest launch-ready patch across mobile and desktop.
Replace generic AI-interface patterns with product-specific visual rules and a bounded implementation plan that preserves working behavior.
Find and repair mobile form friction across keyboards, autofill, validation, focus, recovery, latency, trust, and interruption states.
Map any repo into an interactive D3 dependency graph plus a Markdown onboarding guide.
Generate a complete 30/60/90 day product launch plan.
Audit and harden GitHub Actions workflows against overbroad permissions, secrets exposure, and supply-chain risks.
Save a coding agent's working state before it hits the context limit, then resume on any model. New in v2.0: Recovery Mode rebuilds a handoff from a transcript and your repo even when a session was cut off with nothing saved.
Lint an exported n8n workflow before it ships.
Turn messy PRDs, Notion docs, and user stories into a structured implementation plan.
Generate runnable accessibility regression tests, not just a findings report.
Audit your dbt project for the test and documentation gaps that let bad data ship.
Diagnose why your Docker Compose stack will not come up.
Find the unit tests that pass without testing anything. Coverage numbers lie when the tests are tautological, and AI test generators produce exactly that.
Figure out why your Vercel build or deploy failed without scrolling the whole log.
Run real Playwright E2E tests on your web app.
Map the blast radius of a code change before you run the whole suite.
Catch documentation that drifted from your code: functions, CLI flags, and env vars named in your docs that are gone from the source.
Check ad copy for the editorial issues that get Google and Meta ads disapproved, before you submit.
Find where knowledge is dangerously concentrated in a codebase. From your git history it flags the files only one person has ever touched and the authors who own too much, and estimates the truck factor.
Debug failing GitHub Actions without scrolling 10,000 log lines.
Audit a JavaScript or TypeScript frontend for missing translations and hardcoded UI strings before you ship a new locale.
Lint an OpenAPI spec and diff two versions to catch breaking API changes before they reach consumers.
Audit your frontend build against a performance budget and catch size regressions before you ship.
Turn git history into clean release notes.
Generate a personalized before-you-ship checklist for your app, with the things you have already done pre-checked. Pick your app type and it tailors the list and scans your repo for what is in place.
Generate a shareable stat card for any repo, with an honest health grade: language mix, size, whether tests, docs, and a license are present, and an A-to-F grade.
Turn a messy task description into a clean, conventional git branch name.
Find and remove commented-out dead code across 8 languages (JS, TS, Python, Java, Go, Rust, HTML, CSS) while preserving TODOs, FIXMEs, license headers, disabled tests, and real documentation.
Save, name, list, and restore git stashes without losing track of what is in them.
Generate a complete pull request description from your staged changes, commits, and branch diff.
Presence tools and anti-slop. Protect the name, fix the tells.
Flag avoidable oversharing, self-congratulation, forced intimacy, disclosure, and exaggerated claims without punishing sincerity or harmless awkwardness.
Turn later-life relationship context into a practical compatibility-question map covering independence, family, geography, routines, care, health, and money.
Separate possible indirect hostility from brevity, formality, conflict avoidance, cultural variation, and ordinary frustration without declaring intent.
Make an agent give the essential fact, immediate next action, and principal risk before any optional detail.
Make an agent selective, concise, observant, calm, and precise about boundaries without cat puns or fake animal roleplay.
Check whether a proposed message or action fits the audience, timing, privacy, power dynamics, and recent context.
Rewrite a consequential message without changing its verified facts, decision, boundary, or policy.
Fail closed on missing native review, disagreement, mixed scripts, and invisible controls before permanent lettering.
Surface missing relationship context, mixed register, and unreviewed Japanese business-language patterns.
Block unsupported resume claims, invented metrics, and unattributed first-person founder statements.
Gate localized subtitle cues on timing, anchors, readability profiles, and Unicode hazards.
Flag malformed cue timing, overlaps, empty text, and excessive reading speed in a normalized subtitle timeline.
Inspect marketing-message evidence for one-click unsubscribe headers, HTTPS endpoints, and a visible body marker.
Check campaign links for missing UTMs, duplicate parameters, case drift, off-policy values, and possible PII.
Diagnose broken link previews, repair the metadata and image asset, and produce platform-aware verification without false cache claims.
Run structural QA on your translation files across locales: placeholder mismatches, untranslated strings, length overflow, terminology drift, and missing keys. It checks form, not meaning, so you do not need to speak the language.
Audit a draft against your own voice spec and flag every line that breaks your house style. You define the rules once; it enforces them everywhere.
Scan a draft for the tells that make writing read as AI-generated, so you can revise them in your own voice before publishing.
Hold your bios, footers, and profiles to one brand spec, so the misspelled name and the stale tagline never ship.
Check supplied HTML for missing share metadata, relative image URLs, SVG portability risk, and a common image-dimension preset. Local and read-only.
Check a desired handle against every platform's username rules and find the form that works everywhere. X caps at 15, YouTube and TikTok reject periods, and you usually find out one platform at a time.
Humanize AI writing without changing the facts.
Flag the hidden and look-alike characters lurking in a handle or brand string: the spoofing tricks and display bugs you cannot catch by reading.
Flag every em-dash and AI transition cliche in a draft and get a plain replacement suggestion for each.
Check the exact decoded QR payload for incomplete URLs, listed shorteners, unsafe schemes, narrow format problems, and explicit credential-like fields.
Catch typos, homophones, and near-miss misspellings across code, docs, and markdown, in a commit, your staged changes, a file, or a whole directory.
Turn raw CRM data and lead lists into something a rep can act on.
Audit one completed channel test against its predeclared qualified gate, attribution, owner exclusion, budgets, changed variables, and cooldown.
Map supported product claims to current channel rules, required artifacts, human-authored fields, and a fail-closed submission-readiness gate.
Rank evidence-backed distribution tests by buyer intent, rules, attribution, access, budget, and qualified outcome gates.
Classify launch, outreach, checkout, payment, usage, and review-time evidence without counting views, deployments, sent messages, or owner tests as demand.
Verify customer-specific invoice fields, attachments, destination, submission receipt, acceptance status, correction version, and aging start.
Reconcile active subcontractors with project COI requirements, certificate facts, named entities, limits, endorsements, expiry, and evidence.
Check freight invoice lines against effective-dated rate rules, shipment facts, and approved accessorial evidence before payment review.
Compare invoice lines with original scope, approved change orders, approval evidence, and completion proof before payment review.
Reconcile RFP addenda with the baseline requirement ledger, acknowledgements, deadlines, and response matrix before owner submission review.
Audit renewal dates, notice deadlines, owners, delivery methods, price escalators, and proof before a SaaS contract window closes.
Audit an enriched B2B lead CSV and route every record to SEND_READY, VERIFY_FIRST, or SUPPRESS before outreach begins.
Turn a Search Console CSV into ranked no-click, low-CTR, striking-distance, URL-overlap, and comparable-loss review actions without overclaiming the cause.
Qualify and score a whole lead list with BANT or MEDDIC, automatically.
Batch-enrich a lead-list CSV.
Handle any B2B sales objection with a framework-backed response.
Turn a CRM export or live HubSpot/Salesforce/Pipedrive sync into an executive-ready pipeline report.
Set up and book meetings end to end.
Generate personalized multi-step cold email sequences from a lead CSV.
Pull the real pain points out of your customer feedback so you build what people actually want. Paste a dump of comments, reviews, forum threads, or support tickets and get a ranked, themed list of what hurts, with the quotes behind each one.
Turn deal details into a branded, client-ready deal room.
Run a 10,000-iteration Monte Carlo forecast on your pipeline CSV to get P50/P70/P90 revenue confidence intervals, an ASCII distribution histogram, and what-if scenarios for slipped deal dates.
Turn CRM exports into sales rep scorecards.
Turn an account's contact list into a champion map.
Turn a raw account CSV into balanced sales territories.
For shipping and selling digital products without the busywork.
Find diacritic loss, normalization drift, mixed scripts, and unsafe identity-record collisions without auto-merging people.
Reconcile track order, ISRCs, contributors, splits, territories, flags, and asset references before delivery.
Reconcile price, availability, and evidence-backed claim meaning across multilingual commerce surfaces.
Catch locale-driven number, date, and formula coercion before a CSV import changes business data.
Reconcile SaaS seats, activity, invoices, and HR status into reviewable reclaim candidates without revoking access.
Reconcile seller-supplied inventory, reimbursement, claim, deadline, and manufacturing-cost evidence locally.
Reconcile product image filenames to a SKU roster and flag missing, extra, unknown, and colliding matches.
Catch Shopify product CSV handle, title, SKU, image URL, and overwrite risks before import.
Reconcile agreed sponsor deliverables, approvals, live URLs, measurement windows, usage-rights expiry, invoices, and payment evidence.
Tie normalized marketplace orders, fees, refunds, reserves, settlement lines, and bank deposits to an explicit payout-period ledger.
Check a chargeback case, evidence index, and timeline for reason-specific gaps, broken references, contradictions, and deadline risk before owner review.
Reconcile product-feed, Merchant Center diagnostic, and landing-page snapshot exports to prioritize the conflicts most likely to block product eligibility.
Turn real before-and-after screenshots into comparable marketplace proof with normalized crops, annotations, captions, and claim checks.
Bulk-create Gumroad products from a CSV.
Audit any URL for technical SEO, Core Web Vitals, on-page issues, and content gaps against up to three competitors, then get a ranked, ready-to-hand-off action plan.
Generate three distinct GPT Image 2 cover options with brand colors, storefront sizes, and no partial output sets.
Check a brand deal or sponsorship contract for the clauses that quietly cost creators.
Check an invoice or estimate before you send it.
Bulk-update cover images and thumbnails across your Gumroad catalog from a CSV or a folder of files named by permalink.
Turn a raw meeting transcript (.vtt, .srt, .txt, or pasted) into clean markdown meeting minutes.
Prices and purchase options are shown on Agensi. Instant download. Works with any agent that reads SKILL.md.
Browse the catalog on Agensi