
A security configuration generator for AI coding assistants that ships 12 defensive layers (prompt injection guards, secrets scanning for 35+ patterns, SSRF/eval blockers, PII compliance) plus six stack-specific hardening templates for OAuth, JWT, WebSocket, CORS, file uploads, and image processing. Targets Firebase, Supabase, PocketBase, Appwrite, and Convex backends. Includes portable rulesets for 17 AI tools (Claude, Cursor, Windsurf, Copilot, bolt.new, v0, Replit Agent) and lite configs for small-context models. Implements autonomous agent-to-agent purchase via x402 protocol with USDC on Base. Exposes three free MCP tools (get_preview, get_pricing, get_sample) before payment. Reach for this when spinning up AI-generated auth flows or backend integrations where you need guardrails baked into the assistant's context from day one.