skip to content
fizzgig
sign in
// suite
architectureknow what you builtoperationsknow it’s runningauditknow it’s safe to shipintegrationspricingdocschangelog
// community
sourdough startersproject kicks-off in 1 prompt
sign inrequest access →
audit suite/security/auth_flow_trace
newsecurityv0.3.0pro · $0.002/call

fizzgig__auth_flow_trace

traces every protected route back to its auth check + verifies webhooks.

// ai does this over time

the AI scaffolded /dashboard, /admin, /api/admin - all the protected routes you asked for. it didn't gate any of them. you ship. anyone with the URL is in.

// the tool does

heuristic auth-flow audit. Flags protected-shaped routes (/admin, /dashboard, /account, /api/admin, /api/private) without detectable auth gating - pass files with `// path`-style markers and it names the exact unprotected handler files (per-file attribution); webhook routes without signature verification (stripe constructEvent / crypto.createHmac / svix); auth library drift (mixing next-auth + clerk + supabase + auth0 + iron-session + lucia in one source).

// so you can

ship knowing every /admin route is actually protected. catches the canonical 'AI scaffolded the route, AI forgot the guard' bug.

● new● v0.3.0● pro
// input schema
schema · application/json
{
"type": "object"
"required": [
"project"
]
"properties": {
"project": {
"type": "string"
"description": "the project slug or path"
}
"strict": {
"type": "boolean"
"default": false
"description": "fail on warnings, not just errors"
}
}
}
// output schema
schema · application/json
{
"type": "object"
"properties": {
"ok": {
"type": "boolean"
}
"findings": {
"type": "array"
"items": {
"type": "object"
"properties": {
"severity": {
"enum": [
"info"
"warn"
"high"
"critical"
]
}
"message": {
"type": "string"
}
"fix": {
"type": "string"
}
}
}
}
}
}
// example call from cursor
~/myapp - example output
→ fizzgig__auth_flow_trace(project="myapp")
{
"ok": false,
"findings": [
{ "severity": "high",
"message": "policy uses user_id without auth.uid()",
"fix": "USING (auth.uid() = user_id)" }
],
"scanned": 3, "duration_ms": 142
}
// reviews
@maya.codes★★★★★
2 days ago

caught a policy that would have leaked every user's comments. shipped a fix in 4 minutes.

@solo_at_3am★★★★★
1 week ago

first tool i installed. it's the one that pays for itself.

@vibebuilder★★★★☆
2 weeks ago

works great. one false positive on a join table - easy to ignore.

// primary action

add to your editor

paste this into your mcp config.
.cursor/mcp.json
{
  "fizzgig": {
    "url": "https://mcp.fizzgig.ai",
    "tools": ["auth_flow_trace"]
  }
}
full setup guide →
// pricing
$0.002 / call
included free in pro plan.
// related tools
secret_leak_finder
v0.9.0
→
rls_checker
v0.6.0
→
env_auditor
v0.4.0
→
fizzgig

the fluffy guardian of vibe-coded products. growls at insecure code so you don't have to.

all systems operational

suite

architectureoperationsauditintegrationspricingdocschangelog

community

sourdough startersdiscord (soon)github (soon)x / twitter (soon)rss (soon)

company

aboutcontacttermsprivacycookies
© 2026 fizzgig.
v1.5.0 · 2026-07-26
AI usage: fizzgig uses AI internally (Anthropic Claude, Google Gemini, OpenAI embeddings) to power audit checks, summarise decisions, and rank findings. Content surfaced from these tools is labelled as such in the dashboard. No user data is used to train third-party AI models — see our privacy policy for the full sub-processor list.