Nothing to hand? Load the — a literal provider key, a Memory that forgets on every deploy, a z.any() tool boundary, a while(true) poll that once burned a month's budget, an uncommitted workflow and a leftover legacy API — or the , where the correct verdict is ship-ready and the useful output is what to add next.
Paste the code — the prescan is free
No upload, no AI: the prescan reads your source in the browser and lists what it mechanically found. The agent, workflow, step, tool, memory, MCP, scorer and storage inventory, then the flags — literal API keys, z.any() / z.unknown() at tool and step boundaries, tools without descriptions, createWorkflow chains never sealed with .commit(), new Memory() without a storage adapter, the deprecated legacy workflow API, instructions that interpolate runtime values, execute bodies that fetch and parse with no error handling, while(true) polls and fixed sleeps, schemaless steps, and console.log left in library code. Each group explains why it matters. This part costs nothing and happens while you type, signed in or not — and Copy prescan checklist gives you the whole thing as a file-and-line markdown checklist to keep, including an honest list of what a regex pass cannot see.
The AI reviews it — this is the metered part
A senior AI-platform engineer's pass: a production-readiness posture with the single most important change named, the inventory with each construct's role, and prioritized findings across correctness, reliability, security, maintainability, performance and cost — each with the problem, the concrete impact in production, the fix and a corrected TypeScript fragment. Every prescan flag is confirmed or explicitly set aside. Findings may only cite agents, workflows, steps, tools and identifiers that actually appear in your code. Pricing is honest: a worst-case amount is reserved before the run and only what the run actually uses is charged — the meter next to the button shows both.
Fix, export, re-run
Tick findings off in the page as you fix them — your place is kept across reloads. Copy any single corrected fragment on its own, or every one in a paste-ready block; take the findings as GitHub PR review comments with ```suggestion fences (paste each onto the lines it corrects and GitHub offers Commit suggestion), as a tickable checklist for the ticket, as a CSV, or as Markdown or JSON. Then start fixing. Two free things track the loop from there: the prescan re-runs as you edit and the strip above the run button counts the flags cleared, still open and newly introduced; and once you have run a second review, the result opens with a comparison against the previous one — findings resolved, still open, newly introduced, downgraded or escalated, matched on the construct each names rather than its renumbered id. Both are computed in your browser and cost nothing. Reviews are saved to your SkillSafe account when you are signed in, so they follow you to another machine; restore puts the code back in the form too, and Compare on any past review lines it up against the one on screen.
Derived from the @mastra-ai/mastra skill.