I ship fast with AI agents and I don't have a security team — so every time I deployed, I had no idea if I'd just pushed a hole to real users.
Raw scanner output ("Missing Strict-Transport-Security header") means nothing to me. So I built Forge to turn that noise into plain-English risks with a fix for each, delivered as a weekly report to my inbox.
Key things:
• Add a domain, run a check, read results in plain English — no security background needed.
• Every finding ships with a concrete fix, not just a red flag.
• Passive checks (DNS, SSL/TLS, headers, SEO) run instantly; active checks (crawling, forms, secret leaks) unlock after domain verification.
• Exposed over MCP, so my agent (Cursor, Copilot, Claude, OpenClaw) runs the audit and reads the report — I barely open the UI.
Free while in beta. Built in public — honest feedback welcome: what's the first thing you'd want a tool like this to catch?
Top comments (0)