Skip to main content

lint · typecheck · build — exit codes in the pr

The fix shows up finished.

Paste a link and watch an agent test your app the way an attacker would — free, no account. Connect your repo and it doesn’t hand you homework: it writes the fix, runs your repo’s own lint, typecheck and build, and opens a pull request that’s ready to approve — exit codes attached. What it can’t fix safely, it skips and says why.

No accountNo repo accessmost scans finish in 3–10 minutes

Only scan apps you control or have explicit permission to test — never systems you don't own.

No GitHub? Every finding still ships with a fix prompt you can paste straight into Lovable, Cursor or v0.

See a finished fix and its exit codesor create an account

Shipped with

CursorClaude CodeLovablev0BoltWindsurf

01 — finding it was never the hard part

Three things your AI coder shipped without telling you.

Any scanner will spot them — that part is cheap. The expensive part is fixing each one without breaking the app that grew around it.

Exposed secrets

Your AI coder pasted sk_live_51Hq…tNb8 into the client bundle. It’s in every visitor’s devtools right now.

Broken flows

Iteration 47 fixed the header. Iteration 50 broke checkout. Users don't file bugs — they just leave.

Unprotected admin routes

A hidden nav link is not authentication. Anyone who types the URL is in.

GET /admin → 200 OK

02 — the receipts

What a finished fix actually looks like.

Real output from a real fix run: the finding with its evidence, the pull request that closes it, and the per-check exit codes our harness recorded — not numbers the model reported about itself.

Critical
Secrets

Live Stripe key in client bundle

Evidence

sk_live_…tNb8 — found in /_next/static/chunks/app.js

A live Stripe secret key is embedded in a JavaScript file that every visitor downloads. Anyone with devtools can copy it and start charging on your account.

Fix prompt

Rotate this key in the Stripe dashboard, then move it to a server-side environment variable and read it from a server-only module. Delete the hardcoded copy from the client bundle, then re-run the scan.

gitmend/fix-4f9a2c
Ready to review
Commits
  • 7d3e9f1 fix: remove live Stripe key from client bundle
  • c21b084 fix: require auth on /admin
Verification receipts

Recorded by the GitMend harness — the model cannot edit them.

Verified at commit 4149969.

  • lint — pass — npm run lint, exited 0, 182ms
  • typecheck — pass — npm run typecheck, exited 0, 172ms
  • build — pass — npm run build, exited 0, 174ms
  • browser — not available — browser check not yet machine-run

1 skipped — key rotation can't be done in code.

Evidence is always redacted — first characters and last four, never the full key. Lint, typecheck and build are run and recorded by our harness; the browser check is the agent’s own report, which is why it never shows a machine result here.

03 — how it works

From a pasted link to a fix you just approve.

You paste a link and you approve a pull request. The agents and the harness do everything in between.

  1. 01

    Paste your link

    Drop your app's URL in the box at the top of this page. No account, no repo access, nothing to install.

  2. 02

    Watch it get attacked

    An agent opens your app the way an attacker would — leaked keys, open admin routes, broken signup and checkout — and captures the evidence as it goes.

  3. 03

    See everything, free

    Create a free account and the whole report opens: what's exposed, who could use it, why it matters, with the evidence behind every finding. Each one also carries a fix prompt you can paste straight into whatever built the app.

  4. 04

    Approve the pull request

    Connect the repo and the fix agent patches what it safely can, one minimal commit per finding. Our harness then runs your repo's own lint, typecheck and build and writes each exit code into the PR. The agent also opens the app in a browser and reports what it saw. You review it and merge.

04 — it keeps running

Your next deploy gets the same treatment.

New commits, new scan, same ending: a report you can read, or a pull request with fresh exit codes.

on a schedule

Weekly by default. Daily when you ship fast.

on default-branch change

Repo scans only fire when the default branch has new commits. No wasted runs.

on new findings

You get an email only when new medium-or-higher findings show up. Anything quieter stays in your report.

  • receipts, not claims

    lint, typecheck and build are run by our harness — not reported by the model — whenever your repo has them. Exit codes ship in the PR.

  • never your main branch

    Fixes land on gitmend/fix-* branches only. Main stays yours.

  • your own token

    Read/write access to your repositories. It can never modify your workflows.

  • redacted by default

    Evidence never shows full secrets — first characters and last four, nothing more.

  • no repo required

    Every finding ships with a copy-paste fix prompt for Lovable, Cursor or v0. Pull requests need a connected repo — nothing else does.

05 — pricing

Start free.

Upgrade when your project list grows — not to unlock anything.

Every plan runs the same scanner and the same fix agent — you pay for volume, not features.

Need more? Studio at $99/mo

06 — questions

Frequently asked questions

Plain-English answers — that's the whole point.

GitMend is a security scanner and fix agent for AI-built apps: it tests your deployed app the way an attacker would, then — once you connect your repository — writes the fix and opens one pull request that is ready to approve. The GitMend harness runs your repository's own lint, typecheck and build scripts, when it has them, and writes each command's exit code into that pull request, so the verification is a machine receipt rather than the model's word for it. Scanning takes a deployed URL and no account, and the free tier is enough to see it work. You review the pull request and merge it — GitMend never touches your default branch.

The issues almost every AI-built app ships: live API keys baked into client code, admin routes that trust a hidden nav link, missing security headers, exposed debug endpoints, and broken signup or checkout flows. Every finding comes with evidence — a redacted key, the open route, a screenshot. Nothing speculative.

No. Paste your URL and the scan starts immediately — no signup, no repo access, nothing to install. You watch the agent work live and see a preview of the report. A free account unlocks the full findings, the evidence behind them, a copy-paste fix prompt for every finding, and fix pull requests once you connect a repository.

You still get everything except the pull request. The scan runs on your deployed URL, and once you create a free account every finding opens with its evidence and a fix prompt written for your app — paste it into Lovable, Cursor, v0 or whatever built the thing, and the fix gets applied there. Pull requests, and the lint/typecheck/build exit codes our harness records, need a connected GitHub repository.

No. Every finding is written in plain English — what's exposed, who can use it against you, why it matters. No CVE-speak. And the fix agent turns each finding into a pull request, so you never have to translate a security report into code yourself.

You pick the findings you want fixed, and the fix agent does the work: it clones your repository and applies one minimal commit per finding. Then the GitMend harness — not the model — runs your repository's own lint, typecheck and build scripts, when the repo has them, and records each command and its exit code in the pull request body; the model has no way to edit those numbers. The agent also opens the app in a browser and reports what it saw, which is its own account of the run rather than a machine-recorded receipt. Everything lands in a single pull request — you review it, you merge it.

Never. The fix agent writes only to gitmend/fix-* branches and opens a pull request. It doesn't push to your default branch and doesn't touch your GitHub Actions workflows. Anything it can't fix safely is skipped and explained in the PR.

Yes. Repository access runs on your own scoped GitHub OAuth token. Scan evidence is always redacted — secrets are never displayed in full. URL scans share nothing but the address you type. You can delete projects and reports any time.

The free plan covers 1 project and 3 scans every 30 days — no credit card required. Starter is $9/month for 3 projects and 25 scans. Pro is $29/month for 15 projects, 75 scans, and daily monitoring. Studio is $99/month for 50 projects, 300 scans, and daily monitoring. One-time top-ups are available without a subscription: a $19 Launch Audit (3 credits) or a $10 Credit Pack (20 credits).

Yes. Turn on monitoring and GitMend rechecks each project on a schedule — weekly by default, and daily on Pro and up when you want faster turnaround. Repository scans only run when the default branch has new commits, and you only get an email when new medium-or-higher findings show up.

You review it. You merge it. That’s your part.

Scanning is free. The exit codes come attached to the pull request.