📡 MCP Radar

FarzamHabibi/pre-production-checklist

Pre-production checklists for solo founders. 4,337 items, 88% portable to any stack, 26 stack supplements — plus AI/agent security and the bugs AI coding assistants actually write.

3 stars
1 forks
JavaScript
momentum ▲ 17.0
created 2026-08-27
on radar since 2026-08-30
ai-securityappsecchecklistdevsecopsincident-responseindiehackerslaunch-checklistlighthousellm-securitymcpmcp-serverpre-productionprompt-injectionsecuritysecurity-auditseostartup
View on GitHub ↗Homepage ↗

About pre-production-checklist

Checklists to run before you ship to production.

Built for solo founders and small teams who own the whole stack — the code, the infrastructure, the deploy pipeline, and increasingly the AI agents too — and who don't have a security team to hand it to.

4,337 items across 96 checklists in 5 domains. 88% of them apply to any stack.

Built and maintained by the team at Arioo — where we ship the kind of product this checklist was written for.

I'm a founder at Arioo. Getting ready to launch, I needed a pre-production security review that covered the whole surface we actually ship: a TypeScript backend, a web app, native clients, a deploy pipeline, and a set of AI agents with real tools attached. Nothing I could find covered more than a fraction of that, so I built the checklist myself.

This repository is the checklist, not a report. It is the set of questions, generalized away from our stack and rewritten as a working document anyone can run against their own product.

Two things made it worth publishing rather than keeping:

Solo founders have no security team. You write the code, configure the infrastructure, set up the pipeline, and then you're also the one who has to decide whether it's safe to launch. There's no one to hand it to, and no obvious place to find out what you should have asked. Most public checklists are either too shallow to catch anything real or written for enterprises with a security function.

From the project README.

Maintaining this server?

Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:

[![On MCP Radar](https://mcp.liqiwa.com/badge.svg)](https://mcp.liqiwa.com/s/FarzamHabibi--pre-production-checklist.html)

Related MCP servers

12122J/mcpvet

MCP security scanner — vet a Model Context Protocol server before you add it to Claude Code, Cursor, or Windsurf. Grades it A–F, catching credential theft, tool-poisoning, and install-script payloads

⭐ 10JavaScript
yagyeshVyas/VibeGuard

Free security & privacy scanner for AI-coded apps. 699 rules, 76 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your AI-generated app for l

⭐ 3JavaScript
omaekumiko2-create/kru

Local-first MCP password and credential manager for AI agents. Use passwords, API keys, SSH identities, and TOTP without exposing hidden plaintext to the model.

⭐ 88Rust
flankerhqd/cyvisguard

Security control plane for AI agents — identity and delegation, capability policy, data-flow taint and a live audit trail, enforced over MCP. Guards a real Claude Code end to end.

⭐ 30TypeScript
sgateway/s-gw

Local credential control for AI coding agents.

⭐ 8TypeScript
howshannon/trust-issues

Adversarial security review for AI skills, repos, MCP servers, and packages before you install them. A read-only scanner plus a five-persona reasoning pass, ending in a GO / GO WITH MITIGATIONS / NO-G

⭐ 5Shell

📬 Get the weekly radar in your inbox

The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.