VibeRaven

VibeRaven: AI got your app to demo. VibeRaven gets it to production. The production protocol for AI-built apps. Open source, local-first, MIT.

Website   Install from npm   Join the Discord

npm version npm downloads GitHub stars MIT license skills.sh pack Follow on X

Website · Quickstart · Agent skills · Releases · Discussions

VibeRaven is a pre-deploy repository check for AI-built Next.js apps using Vercel and Supabase. Use it before launch or client handoff, and after migration or policy changes. It reports file evidence and agent tasks for missing RLS, permissive policies, browser-exposed service-role keys, environment variables missing from templates, and Stripe handlers without signature verification. Run npx -y viberaven@1.6.7 in your repo to open Studio, which brings together findings, provider context, release diffs and work through a connected coding CLI. Repository findings do not prove live user isolation or replace a security audit. VibeRaven does not build or deploy your app; verify live policies and provider settings separately.

npx -y viberaven@1.6.7

The Studio opens in your browser and runs on your machine: it detects your stack, finds your providers, shows your release history and diffs, and lists the launch gaps its offline checks find in your repo, with a readiness score. You decide when to ship. The local checks need no login and no API key, and there is no telemetry. “Run full check” is optional: it is a hosted check that needs a VibeRaven account and uses its allowance (see Philosophy).

Your first 5 minutes

  1. Run it. npx -y viberaven@1.6.7 in your project folder. The Studio opens in your browser and scans your repo offline.
  2. Read your verdict. The Studio shows a readiness score out of 100 and the blockers it found in your repo files. Pick one and hand it to your agent to fix.
  3. Connect your coding agent. Pick Codex, Claude Code, or Gemini CLI in the chat panel, hit Test connection, and choose how much access it gets (ask, approve, or full).
  4. Give your agent the skills. Install the six-skill pack and the plugin so Codex, Claude Code, and Gemini follow the same senior-engineer loop everywhere:

    npx -y skills@1.7.0 add ohad6k/VibeRaven --skill viberaven   # skills.sh pack
    npx -y viberaven@1.6.7 init --agents all                     # agent rules in-repo
    

Everything the agent needs is also written to .viberaven/ as markdown and JSON, readable by any tool and versioned by git.

Before deploying a Vercel + Supabase app

Want to find Supabase tables missing RLS in your migrations before launch? Run the before-and-after example. It shows the exact migration finding and how the repo verdict changes after owner policies are added. The check reads repository files; deployed database policies still need separate verification.

What the Studio gives you

Capability What it does
Agent chat on your repo Drive Codex, Claude Code, or Gemini CLI from one cockpit, with connection health and live terminal output.
Access modes ask, approve, or full. The mode changes the real agent command it runs, not just the UI copy.
Versions & releases Release diffs, tags, changelogs, and “what changed since the last working release” in plain English.
Providers via MCP Connect Supabase, Vercel, and Stripe. Provider status flows into agent prompts, and provider proof stays separate from repo-code fixes.

The terminal twin: viberaven check

The same verdict without the Studio:

Output captured from the built VibeRaven 1.6.6 release candidate on a synthetic Next.js + Supabase app (project path shortened):

viberaven check · ~/my-app

🔴 No RLS policy proof in migrations  (rls_disabled)
   1 public table without row level security: public.profiles (supabase/migrations/0001_init.sql:1). The Data API does not enforce row restrictions for roles and operations allowed by the table's grants. Verify those grants to determine who can read or change rows.
🔴 Service role key in a client-prefixed env variable  (service_role_key_in_client_env)
   .env.example:3: NEXT_PUBLIC_SUPABASE_SERVICE_ROLE_KEY names a service role or secret key under the NEXT_PUBLIC_ prefix. NEXT_PUBLIC_* variables are exposed to client code by Next.js, so anyone who loads the app can read it and skip RLS entirely. Rename it without the prefix, read it only in server code, and rotate the key.
⚪ No error monitoring detected  (missing_monitoring)
   No Sentry/PostHog (or similar) instrumentation was found. Production errors will only surface when users complain.

Verdict: ❌ 2 blockers, 0 warnings · score 55
Fix: viberaven fix · Details: ~/my-app\.viberaven\agent-tasklist.md

Each finding names its gap ID, and most name the file that caused it. The command exits 1 when there are blockers. Then:

npx -y viberaven@1.6.7 fix            # list gaps with safe automatic recipes
npx -y viberaven@1.6.7 fix --gap <id> # apply one recipe
npx -y viberaven@1.6.7 --strict       # the verdict as an exit code for CI, if you want one (exit 1 on not_clear; warnings exit 0)

All results land in .viberaven/ as markdown and JSON on disk (agent-tasklist.md, gate-result.json, context-map.json), so any agent and your git history can read them.

In CI: the GitHub Action

Lovable and Bolt push straight to main, so a pull request check alone misses most of their changes. The VibeRaven GitHub Action runs the same check on pull requests and on pushes, in your own runner:

on:
  push:
    branches: [main]
  pull_request:
permissions:
  contents: write
  pull-requests: write
jobs:
  check:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v5
        with:
          fetch-depth: 0
      - uses: ohad6k/viberaven-action@v1

A pull request gets one comment with what the change added or fixed. A push to main gets a commit comment when there is a blocker. It is advice by default; with fail-on-blockers: 'true' the job fails when it finds a blocker, and your branch protection decides what that means for merging. npx -y viberaven@1.6.7 init --github writes a pull-request-only version of this workflow without the Action.

Install for AI agents

Make agents use release and provider context before they patch the repo:

npx -y viberaven@1.6.7 init --agents all
npx -y viberaven@1.6.7 doctor --agents

Preview without writing files:

npx -y viberaven@1.6.7 init --agents all --dry-run

This installs bounded rules (<!-- VIBERAVEN:START --> … <!-- VIBERAVEN:END -->) into:

The rules say when a pass helps (an AI-built app on Vercel + Supabase, before launch or handoff, or after a migration or policy change) and teach the loop: check, read .viberaven/, fix one gap, then check again once per batch of fixes. They are advice, not a gate: the user decides when to ship.

Agent skills

Six skills.sh skills route agents through architecture questions, version evidence, and launch proof:

Skill Job
viberaven The router: local check/fix loop, Studio, and MCP context.
architecture-context Ask the missing product questions before any edit.
architecture-plan Turn answers plus repo evidence into a workstream plan.
what-broke Find which version broke the app before patching.
production-context Keep compact production memory in .viberaven/production-context.md.
go-live Local app to GitHub to Vercel, with live-URL proof.
npx -y skills@1.7.0 add ohad6k/VibeRaven --skill viberaven

See agent-skills/ for the full pack.

This repo also works as an agent plugin: plugin.yaml, .claude-plugin/, .codex-plugin/, and gemini-extension.json expose the six skills plus /viberaven-work, /viberaven-help, /viberaven-production-context, and /viberaven-launch commands to Claude Code, Codex, and Gemini CLI.

For a smaller install, plugins/viberaven is a standalone plugin for Claude Code and Cursor: one skill that says when a pre-launch pass fits a Vercel + Supabase app, plus the MCP server pinned to @viberaven/mcp@1.6.7.

MCP

VibeRaven is listed in the MCP registry for agents that prefer tools over terminal commands:

{ "viberaven": { "command": "npx", "args": ["-y", "@viberaven/mcp@1.6.7"] } }

Key tools: viberaven_check_readiness (runs the local check), viberaven_heal_apply, viberaven_verify, viberaven_audit, viberaven_gate_result, and viberaven_validate_npm_package (run it before adding npm dependencies).

Vercel + Supabase

npx -y viberaven@1.6.7 audit --vercel-supabase

Repository evidence for RLS, service-role exposure, and pooler ports. It reads repo files only, so it cannot show which RLS policies are live in your Supabase project.

Philosophy

Contributing

Contributions are welcome, and most of them need no private source access:

Resources

License

MIT. Current public release: viberaven@1.6.7.

Built by Ohad Krispin (github.com/ohad6k).

If VibeRaven helps you ship, star the repo so other AI app builders can find it. Use Watch → Custom → Releases for release notifications.

This public repo is the agent discovery and installation surface. Product source development happens in a private repository.