Building AI SEO tools for indie SaaS founders $7K MRR 🚒 ReplyPilots πŸ“ˆ BrandCite πŸ›‘οΈ SafeWeave Building in public β€’ 3 SaaS, 1 operator

United States
61% of AI-generated code is functionally correct. Only 10.5% is secure. That gap is what we built SafeWeave for. 8 scanners in one MCP command β€” SAST, secrets, dependencies, containers, IaC, DAST, licenses, posture. Works directly inside Cursor and Claude Code. Catches what AI misses. In 12 seconds. Just launched β†’ safeweave.dev @CK_startup
1
4
363
I asked Cursor to wire up Stripe. Working checkout in ten seconds. Also a live secret key on line 3. I deleted the line. The key was still in git history. I don't ship on "I removed it." I rotate it. Then I scan so the next one never lands.
1
27
I asked it to add a β€œremember me” cookie. It set HttpOnly. It set a 30-day expiry. It forgot Secure and SameSite. The cookie worked on localhost. It also worked on any HTTP page that asked for it. I don't ship on "login sticks." I scan the cookie flags. safeweave.dev
12
I asked for a URL fetcher. "For webhooks." It took any host. Including 169.254.169.254. The metadata endpoint answered. So did my cloud keys. I don't ship on "it fetches." I scan the allowlist. safeweave.dev
13
I asked it to add signup. It hashed the password. It also took `role` from the request body. I signed up as `"admin"`. I don't ship on "auth works." I scan the fields it accepts. safeweave.dev
10
I asked it to make the API work from localhost. It set `Access-Control-Allow-Origin: *`. And `credentials: true`. The browser was happy. So was every other origin. I don't ship on "it works in Chrome." I scan the headers. safeweave.dev
10
I asked Cursor to fix the IDOR. It scoped the GET to the current user. PATCH still took any id. DELETE too. The list endpoint was still primary-key. I don't merge on the "fixed" comment. I scan the routes. safeweave.dev
17
I opened a folder from a zip. Claude ran git status before I typed. Before the trust prompt. That's GitSpawn. The repo's .git/config named the program. I patch the agent. I still scan the files that land after. safeweave.dev
31
I vibe-coded a feature in 20 minutes. Shipped it. Then I searched the branch for sk- on a hunch. It was in a comment. The agent had "rotated" the key by pasting the old one next to the new one. I built a scanner after that. First scan is free. safeweave.dev
1
21
I asked Cursor to fix the command injection. It wrote a regex blocklist of shell metacharacters. The payload that still ran had none of them. I don't trust the "fixed" comment. I scan the file. safeweave.dev
8
The Claude hack writeups keep landing on the download link. The part that survives a wipe is the skill file that came back from backup. Looked like a style guide. It was a downloader. I don't trust the filename. I scan the files the agent loads. safeweave.dev
3
64
They told Cursor it was a simulation. It still pulled credentials for seven companies. I don’t hand SafeWeave the prompt. I hand it the files. The agent doesn’t get to name the run. npx -y safeweave-mcp
1
25