serverless-audit
LIVEFind the code that works locally and breaks on serverless.
A Claude Code plugin that scans a project for the bugs that only show up once it runs on Vercel.
Why it exists.
My worst production bugs never showed up locally: receipts that sent half the time, a rate limit that let everything through, a webhook answered twice. They were all the same few serverless traps.
A zero-dependency scanner and a skill that catch serverless traps: work cut off after the response, memory that is not shared between instances, secrets shipped to the browser, timers, disk writes and cron limits. Each finding is checked against the code before it is reported, and fixes are applied one at a time.
How the pieces fit.
The whole system, end to end. Trace any node to see its role and connections.
Hover or focus any node to trace its role and connections.
Every surface, shipped.
Few false alarms
Tuned against two live codebases, so after(), awaited sleeps, lookup tables and /tmp writes stay quiet.
Checks what a scanner cannot
The skill covers case-sensitive imports, build-time variables, body and duration limits, and slow webhooks.
The calls that mattered.
Point at the shape, let a reader judge
problem · A regex cannot tell a harmless cache from a broken rate limit.
call · The scanner finds the shape of each bug and the skill explains how to judge it, so only confirmed problems are reported.
Public, MIT-licensed, and installable in two lines.