Catalog
55 skills. Not all of them run on your site.
ReadyVibe is a set of specialists rather than one giant instruction blob. Entry skills consider a whole area and route to the specialists that apply; each specialist says when it activates, when it should not, and what it must never claim. Each skill has a focused job; your agent decides which ones the task needs.
Read straight from the repository's current model (opens in a new tab): 55 skills · 40 launch checks · 12 compliance domains.
Broad review skills
Entry skills consider a whole area, decide what applies and route to specialists. After installing ReadyVibe, your agent chooses the relevant skills. launch-all coordinates a launch review.
- Activates when
- someone asks whether a website or web app is ready to launch, or wants a pre-launch review of a vibe-coded or AI-generated site. It inspects the real product, decides which of the 40 launch checks apply, routes only to the specialists that can help, fixes what is safe, verifies the result, and reports what still needs a human.
- Does not activate
- to run every ReadyVibe skill, to certify legal compliance, or for a single-topic request that one specialist already covers.
- Owns launch checks
- Checks 1–40. .
- Companions
- site-reconnaissance, design-system-reconnaissance, launch-verification, compliance-all, discoverability-all, trust-all, quality-all, production-all, regulated-domain-triggers, consumer-protection-readiness, payments-readiness, subscription-readiness, admin-authorization, admin-audit-log, admin-dashboard Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site or app needs a privacy, consent, communications, age, data-rights, commerce, or legal-disclosure review, or when someone asks "are we GDPR/CCPA compliant?". It works out which of the 12 compliance domains apply from evidence, activates only those specialists, verifies behavior against disclosures, and states what needs legal review.
- Does not activate
- to force a cookie banner or a policy onto a site that does not need one, to run every legal skill, or to certify compliance.
- Owns launch checks
- Checks 1–8. .
- Companions
- jurisdiction-applicability, site-reconnaissance, cookie-and-storage-audit, data-flow-mapping, policy-consistency, privacy-policy, terms-of-service, privacy-readiness, consent-management, analytics-privacy, third-party-privacy, email-compliance, minors-readiness, data-rights, consumer-protection-readiness, subscription-readiness, payments-readiness, wcag-readiness, web-security, security-headers, deployment-cleanup, regulated-domain-triggers, ai-features-readiness, legal-identity-notices, public-support, legal-navigation Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a public site should be found and shared correctly, or when titles, descriptions, canonicals, robots.txt, sitemap.xml, social previews, favicon, and indexing directives need one coordinated review. It runs one shared sweep, then routes only to the specialists whose findings need work.
- Does not activate
- as a ranking promise, for a private or intentionally unindexed product beyond confirming it is consistently noindex, or for a single-file fix a specialist already owns.
- Owns launch checks
- Checks 9–18. .
- Companions
- seo-readiness, social-sharing, launch-identity, deployment-cleanup, search-console-readiness, structured-data, multilingual-readiness, link-integrity Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site is about to go live and its forms, email unsubscribe, secrets, staging leftovers, security headers, or performance have not been verified. It runs one shared production sweep and routes to the forms, email, security, and performance specialists.
- Does not activate
- for penetration testing, load testing, or certifying security, and do not use it to send real email or submit real forms on a live site.
- Owns launch checks
- 35 Forms actually submit and handle outcomes · 36 Unsubscribe works where marketing email exists · 37 Unsubscribe results in suppression · 38 Exposed secrets, client env mistakes, debug artifacts · 39 HTTPS / security headers / CSP / production sanity · 40 Performance
- Companions
- forms-readiness, email-compliance, web-security, deployment-cleanup, security-headers, dependency-security, performance-readiness, admin-authorization, admin-audit-log, admin-dashboard Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site needs a combined accessibility and responsive-quality review: alt text, headings, keyboard use, focus, contrast, form labels, reduced motion, phone and tablet layouts, overflow, tables, dialogs, touch targets, sticky bars. It runs one shared runtime pass and routes to the accessibility and mobile specialists.
- Does not activate
- to claim WCAG conformance, to replace assistive-technology testing, or for backend or SEO work.
- Owns launch checks
- Checks 27–34. .
- Companions
- wcag-readiness, forms-readiness, mobile-readiness, rtl-readiness, multilingual-readiness Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site looks finished but may still feel unfinished or untrustworthy to visitors: unclear main action, dead buttons, placeholder text, fake or unverifiable claims, missing contact path, weak 404, broken links, or missing loading and error states. It coordinates the trust-related specialists and verifies the fixes.
- Does not activate
- to add trust badges, invent testimonials or metrics, or manufacture an FAQ the product does not need.
- Owns launch checks
- Checks 19–26. .
- Companions
- content-trust, faq-readiness, error-pages, link-integrity, failure-resilience, public-support, launch-identity, legal-navigation Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- someone asks for an admin dashboard, back office, or operator panel, or when a launched product needs operators to manage users, content, payments, subscriptions, support messages, privacy requests, or moderation. It reads the actual application, works out what this product's operators need, and builds a complete admin tailored to that product and to the project's existing design system, with server-side authorization and only real data.
- Does not activate
- to paste in a generic admin template, to show invented revenue, charts, growth, or users, or to impose a new visual style.
- Owns launch checks
- 24 Loading, empty, success, failure, recovery states · 37 Unsubscribe results in suppression
- Companions
- design-system-reconnaissance, admin-authorization, admin-audit-log, data-rights, wcag-readiness, forms-readiness, mobile-readiness, failure-resilience Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site needs an FAQ or help section, or when visitors predictably have questions about pricing, billing, cancellation, data, delivery, or how the product works that the site does not answer at the point of decision. It works out the real questions from the product, its support traffic, and its own policies, writes answers only from facts it can verify, and builds the FAQ in the project's existing design.
- Does not activate
- to invent questions or answers, to pad a self-explanatory site with a generic FAQ, or to write legal, refund, or privacy wording the owner has not published.
- Owns launch check
- 20 FAQ / help content
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
Core 10
Broad entry skills and the foundations they lean on: recon, design-system reading, verification.
- Activates when
- a site or app needs a privacy, consent, communications, age, data-rights, commerce, or legal-disclosure review, or when someone asks "are we GDPR/CCPA compliant?". It works out which of the 12 compliance domains apply from evidence, activates only those specialists, verifies behavior against disclosures, and states what needs legal review.
- Does not activate
- to force a cookie banner or a policy onto a site that does not need one, to run every legal skill, or to certify compliance.
- Owns launch checks
- Checks 1–8. .
- Companions
- jurisdiction-applicability, site-reconnaissance, cookie-and-storage-audit, data-flow-mapping, policy-consistency, privacy-policy, terms-of-service, privacy-readiness, consent-management, analytics-privacy, third-party-privacy, email-compliance, minors-readiness, data-rights, consumer-protection-readiness, subscription-readiness, payments-readiness, wcag-readiness, web-security, security-headers, deployment-cleanup, regulated-domain-triggers, ai-features-readiness, legal-identity-notices, public-support, legal-navigation Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- reviewing a pull request, branch, or release for launch and privacy impact: new vendors or third-party hosts, new personal-data fields or forms, new routes, changed consent or email behavior, new storage. It reads the change and lists what it introduces and which ReadyVibe specialists should recheck.
- Does not activate
- as a substitute for a full review or to approve a release as compliant.
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- about to create or change any visible UI in a project, such as a 404 page, legal page, consent control, or footer link, to record the design tokens, components, layout patterns, and copy tone already in use so new pieces look native.
- Does not activate
- to design a new visual style, to redesign the site, or when no visible UI will be created or changed.
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a public site should be found and shared correctly, or when titles, descriptions, canonicals, robots.txt, sitemap.xml, social previews, favicon, and indexing directives need one coordinated review. It runs one shared sweep, then routes only to the specialists whose findings need work.
- Does not activate
- as a ranking promise, for a private or intentionally unindexed product beyond confirming it is consistently noindex, or for a single-file fix a specialist already owns.
- Owns launch checks
- Checks 9–18. .
- Companions
- seo-readiness, social-sharing, launch-identity, deployment-cleanup, search-console-readiness, structured-data, multilingual-readiness, link-integrity Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- someone asks whether a website or web app is ready to launch, or wants a pre-launch review of a vibe-coded or AI-generated site. It inspects the real product, decides which of the 40 launch checks apply, routes only to the specialists that can help, fixes what is safe, verifies the result, and reports what still needs a human.
- Does not activate
- to run every ReadyVibe skill, to certify legal compliance, or for a single-topic request that one specialist already covers.
- Owns launch checks
- Checks 1–40. .
- Companions
- site-reconnaissance, design-system-reconnaissance, launch-verification, compliance-all, discoverability-all, trust-all, quality-all, production-all, regulated-domain-triggers, consumer-protection-readiness, payments-readiness, subscription-readiness, admin-authorization, admin-audit-log, admin-dashboard Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a fix or a finding needs proof: re-checking behavior after a change, confirming a blocker is really gone, or turning collected evidence into a scoped launch verdict. It re-runs the original evidence, records what changed, and separates verified, unverified, and review-required items.
- Does not activate
- to declare a site legally compliant, or as a substitute for the specialist that found the problem.
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site is about to go live and its forms, email unsubscribe, secrets, staging leftovers, security headers, or performance have not been verified. It runs one shared production sweep and routes to the forms, email, security, and performance specialists.
- Does not activate
- for penetration testing, load testing, or certifying security, and do not use it to send real email or submit real forms on a live site.
- Owns launch checks
- 35 Forms actually submit and handle outcomes · 36 Unsubscribe works where marketing email exists · 37 Unsubscribe results in suppression · 38 Exposed secrets, client env mistakes, debug artifacts · 39 HTTPS / security headers / CSP / production sanity · 40 Performance
- Companions
- forms-readiness, email-compliance, web-security, deployment-cleanup, security-headers, dependency-security, performance-readiness, admin-authorization, admin-audit-log, admin-dashboard Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site needs a combined accessibility and responsive-quality review: alt text, headings, keyboard use, focus, contrast, form labels, reduced motion, phone and tablet layouts, overflow, tables, dialogs, touch targets, sticky bars. It runs one shared runtime pass and routes to the accessibility and mobile specialists.
- Does not activate
- to claim WCAG conformance, to replace assistive-technology testing, or for backend or SEO work.
- Owns launch checks
- Checks 27–34. .
- Companions
- wcag-readiness, forms-readiness, mobile-readiness, rtl-readiness, multilingual-readiness Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- you need to know what a website or web app actually is and does before reviewing or changing it: its framework, routes, audience, accounts, payments, email, analytics, forms, third parties, and deployment. It builds a short evidence-labeled context from the repository, config, and running site without a questionnaire.
- Does not activate
- to draft policies, apply fixes, or ask the user questions the repository can answer.
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site looks finished but may still feel unfinished or untrustworthy to visitors: unclear main action, dead buttons, placeholder text, fake or unverifiable claims, missing contact path, weak 404, broken links, or missing loading and error states. It coordinates the trust-related specialists and verifies the fixes.
- Does not activate
- to add trust badges, invent testimonials or metrics, or manufacture an FAQ the product does not need.
- Owns launch checks
- Checks 19–26. .
- Companions
- content-trust, faq-readiness, error-pages, link-integrity, failure-resilience, public-support, launch-identity, legal-navigation Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
Compliance 18
Privacy, consent, email, age, rights, vendors and legal notices. Facts first, legal conclusions left to people.
- Activates when
- a product calls a language model or other AI API, embeds AI-generated content, or offers a chatbot, and you need to check provider keys and exposure, what user data reaches the provider, disclosure that users are dealing with AI, abuse and cost controls, and failure behavior.
- Does not activate
- to add a generic AI disclaimer to a product with no user-facing AI, to judge model quality, or to interpret AI regulation.
- Owns launch check
- 38 Exposed secrets, client env mistakes, debug artifacts
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site includes analytics, advertising pixels, session replay, heatmaps, or a tag manager and you need to know what they collect, when they fire, and whether the disclosure and any consent gating match. It inventories vendors and personal-data exposure and verifies timing at runtime.
- Does not activate
- to install analytics, to certify a vendor as compliant, or to state that analytics needs or does not need consent without looking up the rule at an official source.
- Owns launch check
- 05 Analytics / tracker inventory and behavior
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site has analytics, advertising, session replay, or other optional trackers and a consent control exists or may be needed. It determines whether gating is applicable by looking up the current rule at an official source, then verifies the behavior of reject, accept, and withdraw, not the appearance of the banner.
- Does not activate
- to add a cookie banner to a site with nothing to gate, to decide legal applicability from memory, or to design a dark-pattern consent flow.
- Owns launch check
- 04 Consent behavior
- Companions
- cookie-and-storage-audit, design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a product shows prices, sells goods or services, offers trials, subscriptions, or refunds, and you need to check that pricing, fees, renewal, cancellation, refund terms, delivery, and merchant identity are shown clearly and consistently across page, checkout, terms, and emails.
- Does not activate
- to invent refund or cancellation terms, to state consumer-law requirements from memory, or for sites that take no money and show no offers.
- Owns launch checks
- 02 Terms of service · 25 Contact / support path
- Companions
- design-system-reconnaissance, subscription-readiness, payments-readiness Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- you need a factual map of what personal data a site collects and where it goes: form fields, account data, database columns, API routes, cookies and identifiers, and every recipient from vendors to email and analytics. It is the input for privacy notices, deletion flows, and vendor reviews.
- Does not activate
- to decide a legal basis, to write the notice, or to guess flows you cannot find in code or traffic.
- Owns launch checks
- 01 Privacy policy · 07 Account / data deletion
- Companions
- cookie-and-storage-audit Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a product has accounts or stored personal data, or a policy promises access, correction, deletion, export, or opt-out, and you need to verify what those actions really do. It traces deletion, export, and opt-out through code and stored state.
- Does not activate
- to describe active=false as permanent deletion, to run destructive actions on real data, or to state which rights or deadlines apply legally.
- Owns launch checks
- 07 Account / data deletion · 37 Unsubscribe results in suppression
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a product sends email or collects addresses for newsletters, product updates, promotions, or lifecycle campaigns, and you need to verify sender identity, transactional versus marketing separation, and that unsubscribe actually suppresses future sends. It traces the unsubscribe from link to stored state to the send path.
- Does not activate
- to stop at the presence of a link, to send real email to real people, or to state legal sufficiency.
- Owns launch checks
- 36 Unsubscribe works where marketing email exists · 37 Unsubscribe results in suppression
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- privacy, consent, consumer, or accessibility questions depend on where users and the business are, and you need to record markets and audience from evidence and see which official sources to consult for them. It separates declared from inferred markets and marks unresolved applicability as review required.
- Does not activate
- to state which laws apply from memory, to pick a jurisdiction for the user, or to invent obligations.
- Owns launch checks
- 04 Consent behavior · 06 Age / audience handling
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a public product needs to show who operates it and carry the notices its assets require: business or operator identity, copyright and trademark statements, open-source and image or font licenses, attribution, and takedown or contact routes for content. It finds missing or inconsistent identity and license notices and marks owner-only facts.
- Does not activate
- to invent a company name, address, registration number, or license text, or to give IP legal advice.
- Owns launch checks
- 08 Business / contact / privacy contact · 25 Contact / support path
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site or app may be used by children or teenagers, collects age or date of birth, or states an audience rule such as 18+. It checks who the product is evidently for, whether age is collected or implied, and whether behavior contradicts the stated audience.
- Does not activate
- to bolt on a decorative age gate, to bypass an age restriction, or to decide which child-protection law applies.
- Owns launch check
- 06 Age / audience handling
- Companions
- analytics-privacy, third-party-privacy, design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site already has a privacy page, cookie notice, banner, terms, badges, or marketing claims about data and you need to compare what it says with what the product does: trackers, forms, cookies, storage, deletion, email, third parties. It reports contradictions and omissions as evidence-backed mismatches.
- Does not activate
- to rewrite the product to match a template, to certify a policy, or to compare against laws from memory.
- Owns launch checks
- 01 Privacy policy · 03 Cookie / tracker disclosure · 26 Claims, metrics, testimonials, social proof
- Companions
- cookie-and-storage-audit, data-flow-mapping, data-rights, email-compliance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site needs a privacy notice, or an existing one must reflect real behavior: it inspects what is collected, by whom, for what, and where it goes, separates supported facts from missing owner facts, and drafts only what evidence supports with clearly marked gaps.
- Does not activate
- to paste generic boilerplate, to invent addresses, retention periods, legal bases, or contacts, or to state that the notice makes the site compliant.
- Owns launch check
- 01 Privacy policy
- Companions
- data-flow-mapping, cookie-and-storage-audit, analytics-privacy, third-party-privacy, data-rights, email-compliance, minors-readiness, payments-readiness, policy-consistency, design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a product stores or processes personal data and you need to judge minimization, retention signals, exposure of personal data in URLs, logs, client storage, or public routes, and whether stored data is protected sensibly. It finds unintended exposure and unused collection.
- Does not activate
- to certify privacy compliance, to choose retention periods, or to remove data the product needs.
- Owns launch checks
- 01 Privacy policy · 07 Account / data deletion
- Companions
- data-flow-mapping Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- starting a launch review, and again whenever features change, to detect whether a product touches a regulated or high-risk domain: health, finance and payments, education, children, legal or professional advice, employment, insurance, crypto, gambling, alcohol or cannabis, biometrics, precise location, or automated decisions. It stops ordinary web-compliance assumptions and routes to human specialist review.
- Does not activate
- to interpret those regimes or to clear a product as unregulated.
- Owns launch check
- 06 Age / audience handling
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a product with accounts, user content, purchases, subscriptions, or usage rules needs terms, or existing terms must match what the product actually does. It inspects features and drafts only supported sections, marking owner-only facts such as governing law, liability, and fees as gaps.
- Does not activate
- to paste boilerplate, to invent governing law or liability limits, or to add terms to a site that makes no commitments.
- Owns launch check
- 02 Terms of service
- Companions
- user-content-safety, payments-readiness, subscription-readiness, consumer-protection-readiness, ai-features-readiness, policy-consistency, design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site loads scripts, fonts, maps, video, chat, captcha, payment widgets, CDNs, or SDKs from other origins and you need to know who receives visitor data and whether that is disclosed and necessary. It maps every third-party host observed or indicated, what each sees, and what to review.
- Does not activate
- to declare a vendor illegal, to judge transfer legality, or to remove a dependency the product needs without asking.
- Owns launch checks
- 03 Cookie / tracker disclosure · 05 Analytics / tracker inventory and behavior
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- users can publish, upload, comment, message, or share content that others can see, and you need to check reporting routes, moderation hooks, abuse controls, and stored-content risks such as XSS and unsafe uploads.
- Does not activate
- to add a moderation queue or reporting flow to a product with no user-visible user content, or to provide legal advice about platform liability.
- Owns launch check
- 38 Exposed secrets, client env mistakes, debug artifacts
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
Discoverability 4
Titles, canonicals, robots, sitemaps, social previews, structured data, search-console readiness.
- Activates when
- a site is publicly live or about to be, and the owner wants search engine verification and sitemap submission prepared. It checks that the property and sitemap can be verified, prepares the exact steps and files an owner must authorize, and states what only Search Console data can show.
- Does not activate
- to claim a page is indexed, to submit or verify on the owner's behalf without permission, or before the production URL is final.
- Owns launch checks
- 12 robots.txt · 13 sitemap.xml
- Companions
- seo-readiness Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- public pages should be found in search, and titles, meta descriptions, canonicals, robots.txt, sitemap.xml, indexing directives, and URL consistency need to be correct and agree with each other. It checks rendered output and the relationships between files, and repairs localhost canonicals, private routes in sitemaps, and starter metadata.
- Does not activate
- to promise indexing or ranking, to keyword-stuff, or on a product that is intentionally private.
- Owns launch checks
- Checks 9–13, 16, 18. .
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a page is genuinely an article, product, organization, local business, event, FAQ, or breadcrumb and JSON-LD structured data exists or would truthfully describe visible content. It validates that markup parses and matches what visitors see.
- Does not activate
- to invent ratings, reviews, prices, or FAQs, to add schema for its own sake, or to chase rich results the content does not merit.
- Owns launch check
- 18 Public URL consistency
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
Accessibility 1
WCAG readiness: what a scan and a keyboard can show, and where a specialist is still needed.
- Activates when
- a site should be usable with a keyboard, screen reader, zoom, and different vision and motion needs: image alternatives, semantic structure and headings, keyboard operation and visible focus, contrast, form labels and errors, dialogs, reduced motion, and touch targets. It checks rendered behavior and fixes what is clearly wrong.
- Does not activate
- to claim WCAG conformance from an automated scan, to invent alt text a scanner wants, or to assert a legal accessibility outcome.
- Owns launch checks
- 27 Image alt text / non-text alternatives · 28 Semantic structure / headings · 29 Keyboard navigation / visible focus · 30 Form labels, instructions, accessible errors · 31 Contrast / readability · 32 Reduced motion
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
Quality 11
Trust, links, 404s, forms, mobile, performance, identity and support: the launch basics.
- Activates when
- a site should make its purpose and next step clear and its content should be real: primary call to action, dead-end pages, placeholder or lorem text, fake or unverifiable metrics, testimonials and logos, misleading claims, unfinished UI. It removes or flags fakes and verifies controls work.
- Does not activate
- to build an FAQ (use faq-readiness), to invent testimonials, metrics, or customers, to force a giant CTA onto every page, or to write marketing copy the owner has not approved.
- Owns launch checks
- 19 Clear primary CTA · 23 Dead buttons, fake controls, placeholders · 26 Claims, metrics, testimonials, social proof
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a routed site needs a launch-quality 404 (and 500) experience: unknown URLs must return a real 404 status, render in the product's own design, help the visitor recover with useful navigation, and expose no debug details. It verifies status codes and fixes framework defaults and soft-404s.
- Does not activate
- to add a decorative page served with status 200, to invent site sections for the links, or for expected redirects.
- Owns launch check
- 21 Custom 404 with recovery
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a UI loads data, calls APIs, or performs actions that can be slow, empty, or fail, and you need to check loading, empty, success, error, and recovery states: no infinite spinners, no blank screens, no swallowed errors, no lost input. It exercises failure paths and fixes states in the existing design.
- Does not activate
- to add spinners everywhere, to hide failures behind fake success, or for static pages with no data fetching.
- Owns launch checks
- 24 Loading, empty, success, failure, recovery states · 35 Forms actually submit and handle outcomes
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site needs an FAQ or help section, or when visitors predictably have questions about pricing, billing, cancellation, data, delivery, or how the product works that the site does not answer at the point of decision. It works out the real questions from the product, its support traffic, and its own policies, writes answers only from facts it can verify, and builds the FAQ in the project's existing design.
- Does not activate
- to invent questions or answers, to pad a self-explanatory site with a generic FAQ, or to write legal, refund, or privacy wording the owner has not published.
- Owns launch check
- 20 FAQ / help content
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site has forms (contact, signup, login, waitlist, checkout, search, feedback) and you need to verify that they are labeled, validated, submit to a working endpoint, and handle loading, success, error, and duplicate submission. It exercises forms safely against local or staging with planted test data and checks where the data goes.
- Does not activate
- to submit forms on a live production site without authorization, to send real messages, or to invent form endpoints or backends.
- Owns launch checks
- 30 Form labels, instructions, accessible errors · 35 Forms actually submit and handle outcomes · 23 Dead buttons, fake controls, placeholders
- Companions
- design-system-reconnaissance, wcag-readiness Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site still carries generator or template leftovers, or its product identity is inconsistent: starter titles like Vite or Next, default favicons, placeholder company names, wrong product names in metadata and emails, missing app icons and manifest, mixed-up logos. It aligns name, titles, icons, and manifest with owner-supplied identity.
- Does not activate
- to invent a company or legal entity name, to design a logo, or to rebrand.
- Owns launch checks
- 15 Favicon / app icons · 09 Page titles · 26 Claims, metrics, testimonials, social proof
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- links, buttons, and route targets across a site must actually resolve: navigation, footer, CTAs, content links, canonical and sitemap targets, mailto and tel links, form actions, and external references. It separates confirmed broken routes from transient network failures and repairs internal links safely.
- Does not activate
- to declare an external site broken from a single timeout, to crawl a site you do not have permission to test, or to replace browser testing of client-side interactions.
- Owns launch checks
- 22 Broken internal / external links · 23 Dead buttons, fake controls, placeholders · 17 Staging / localhost / test references
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site must work on phones and tablets, and you need real evidence from rendered layouts at small viewports: viewport meta, horizontal overflow, navigation, reading width, forms, tables, dialogs, touch targets, sticky bars, and whether the main task can be completed.
- Does not activate
- to treat "no horizontal scrollbar" as mobile readiness, to claim device coverage from one emulated size, or to redesign the site.
- Owns launch checks
- 33 Mobile / responsive behavior · 34 Mobile overflow, tables, dialogs, touch targets, sticky UI
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- public pages must load acceptably before launch and you want practical evidence of high-impact waste: oversized images, huge JavaScript bundles, render-blocking scripts, unnecessary fonts and third parties, unsized media causing layout shift, and heavy above-the-fold content. It records lab signals and fixes obvious waste.
- Does not activate
- to promise a Lighthouse score or Core Web Vitals outcome, to invent field data, or as a performance laboratory.
- Owns launch check
- 40 Performance
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a public product needs a working way for visitors to reach a human: support, privacy, and business contact paths that exist, work, and match what pages promise. It checks addresses, forms, and consistency, and repairs broken or placeholder contact routes with owner-provided details.
- Does not activate
- to invent an email address, phone number, or physical address, to promise response times the owner has not set, or to add live chat nobody will staff.
- Owns launch checks
- 08 Business / contact / privacy contact · 25 Contact / support path
- Companions
- design-system-reconnaissance, forms-readiness Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
Security 4
Exposed secrets, deployment leftovers, headers and dependencies.
- Activates when
- a project has package manifests and lockfiles and you want to know about known-vulnerable, abandoned, or suspicious dependencies before launch, without running install scripts. It reads manifests and lockfiles, uses the ecosystem's audit tooling where safe, and proposes minimal, non-breaking upgrades.
- Does not activate
- to upgrade major versions automatically, run untrusted install scripts, or claim a project is free of vulnerabilities.
- Owns launch checks
- 39 HTTPS / security headers / CSP / production sanity · 38 Exposed secrets, client env mistakes, debug artifacts
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site must be cleaned of development, staging, and test artifacts before going live: localhost and staging URLs, preview hostnames, test data and accounts, debug routes, source maps, console noise, placeholder environment values, and mismatches between build modes. It finds them in source, config, and shipped output and repairs the safe ones.
- Does not activate
- for penetration testing, for deployment itself, or to modify production infrastructure or environment values.
- Owns launch checks
- 17 Staging / localhost / test references · 38 Exposed secrets, client env mistakes, debug artifacts
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- a site is deployed or about to be, and you need to inspect HTTPS, redirects, HSTS, and response security headers, and to propose a Content-Security-Policy based on the origins the site actually loads. It reads live headers and the observed vendor list, then drafts a policy in report-only form first.
- Does not activate
- to paste a generic script-src 'self' policy, to break third-party functionality, or to judge production headers from a local dev server.
- Owns launch check
- 39 HTTPS / security headers / CSP / production sanity
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- preparing a public launch of a site or app that has client and server code, environment variables, accounts, or APIs, to find launch-blocking security mistakes: exposed secrets and client-side env misuse, missing authorization on routes and APIs, publicly reachable private routes, debug endpoints, unsafe redirects and rendering, and insecure session handling. It reports evidence and fixes clear low-risk issues.
- Does not activate
- as a penetration test, to claim a site is secure, to use or rotate credentials, or to treat a hidden admin link as authorization.
- Owns launch checks
- 38 Exposed secrets, client env mistakes, debug artifacts · 16 Indexing sanity
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
Admin 3
A full operator admin built from your real data model, with authorization and audit trail.
- Activates when
- admins, staff, or support can perform destructive or sensitive actions such as deleting users, changing roles, issuing refunds, exporting data, impersonating, or changing settings, and you need to check that these actions leave a durable who-did-what record without storing secrets.
- Does not activate
- to build a logging platform, to log passwords, tokens, or full personal data, or when no privileged actions exist.
- Owns launch check
- 38 Exposed secrets, client env mistakes, debug artifacts
- Companions
- admin-authorization Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- someone asks for an admin dashboard, back office, or operator panel, or when a launched product needs operators to manage users, content, payments, subscriptions, support messages, privacy requests, or moderation. It reads the actual application, works out what this product's operators need, and builds a complete admin tailored to that product and to the project's existing design system, with server-side authorization and only real data.
- Does not activate
- to paste in a generic admin template, to show invented revenue, charts, growth, or users, or to impose a new visual style.
- Owns launch checks
- 24 Loading, empty, success, failure, recovery states · 37 Unsubscribe results in suppression
- Companions
- design-system-reconnaissance, admin-authorization, admin-audit-log, data-rights, wcag-readiness, forms-readiness, mobile-readiness, failure-resilience Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
Internationalization 2
Multilingual and right-to-left readiness.
- Activates when
- a site offers more than one language or locale, and you need to check locale routing, html lang, hreflang and canonicals per language, untranslated fallbacks, and whether trust and legal pages exist in each language.
- Does not activate
- to translate content yourself without the owner's approval, to call a site multilingual when key pages are missing in a language, or on single-language sites.
- Owns launch checks
- 18 Public URL consistency · 09 Page titles
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- an RTL language such as Arabic, Hebrew, Persian, or Urdu is served or planned, and layout and behavior must mirror correctly: dir attribute, logical CSS properties, mirrored navigation, bidi text, icons, and forms. It checks rendered pages in RTL and fixes layout logic.
- Does not activate
- to mirror non-directional icons, to flip images with text, or on sites with no RTL locale.
- Owns launch checks
- 33 Mobile / responsive behavior · 28 Semantic structure / headings
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
Commerce 2
Payments and subscriptions.
- Activates when
- a site takes payments through a provider such as Stripe, Paddle, Lemon Squeezy, or PayPal and you need to check integration mode, key handling, webhook verification, and that the checkout flow works and never touches card data. It verifies test versus live configuration and exercises checkout in test mode only.
- Does not activate
- to store card numbers, to enter real payment details, to move money, or to judge payment regulation.
- Owns launch checks
- 38 Exposed secrets, client env mistakes, debug artifacts · 35 Forms actually submit and handle outcomes
- Companions
- None. Works entirely on its own.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
- Activates when
- billing recurs: subscriptions, trials that convert, auto-renewing plans, or metered billing. It checks that renewal, trial conversion, price changes, and cancellation are disclosed, actually work in the billing system, and agree across page, checkout, terms, and emails.
- Does not activate
- on products without recurring billing, to invent cancellation or refund terms, or to state renewal-law requirements from memory.
- Owns launch checks
- 02 Terms of service · 35 Forms actually submit and handle outcomes
- Companions
- design-system-reconnaissance Installed: full method. Not installed: a reduced-depth fallback, reported as such.
Install ReadyVibe npx skills add moh-obaida/ReadyVibe-SkillsRead SKILL.md on GitHub (opens in a new tab) · Folder (opens in a new tab)
These are the 40 launch areas ReadyVibe knows how to inspect, grouped into five families. During a real review, it inspects the project and decides which areas actually need work. Every check has an owning skill.
A Compliance and privacy via
- 01
Privacy policy
Does a policy exist that describes what this product actually collects, uses, and shares?
Owneralso policy-consistency, data-flow-mapping - 02
Terms of service
Do terms exist that match the accounts, content, payments, and rules the product really has?
Owneralso legal-navigation - 03
Cookie / tracker disclosure
Is every cookie, storage key, and third-party tracker that actually loads described?
Owneralso policy-consistency, third-party-privacy - 04
Consent behavior
When consent is required, do reject, accept, and withdraw really change behavior?
Owneralso jurisdiction-applicability - 05
Analytics / tracker inventory and behavior
What analytics, ads, replay, and pixels exist, when do they fire, and what do they receive?
Owneralso cookie-and-storage-audit, third-party-privacy - 06
Age / audience handling
Who is this for, is age collected or implied, and does behavior contradict the stated audience?
Owneralso regulated-domain-triggers - 07
Account / data deletion
Does deleting an account or data actually delete or anonymize what it claims?
Owneralso privacy-readiness - 08
Business / contact / privacy contact
Can a visitor tell who runs this and how to reach them about privacy and support?
Owneralso legal-identity-notices
B Discoverability via
- 09
Page titles
Is every public page's title unique, specific, and not a framework default?
Owneralso launch-identity - 10
Meta descriptions
Does each public page have a real, page-specific description?
Owneralso social-sharing - 11
Canonical URLs
Do canonicals point at the correct production URL of each page?
Owneralso check-links helper - 12
robots.txt
Does robots.txt allow what should be found and stay honest about what is private?
Owneralso search-console-readiness - 13
sitemap.xml
Does the sitemap list exactly the canonical, public, live URLs?
Owneralso search-console-readiness - 14
Open Graph / social share
Does a shared link show a correct title, description, and working image?
Owneralso seo-readiness - 15
Favicon / app icons
Are tab icon, touch icon, and manifest icons real, present, and not starter assets?
Owneralso social-sharing - 16
Indexing sanity
Are public pages indexable, private pages not, and do signals agree?
Owneralso web-security - 17
Staging / localhost / test references
Does any shipped page, config, or link still point at a dev or staging host?
Owneralso seo-readiness, link-integrity - 18
Public URL consistency
Do canonical, sitemap, metadata, redirects, and links agree on one host, scheme, and path form?
Owneralso discoverability-all
C Trust and product readiness via
- 19
Clear primary CTA
Can a first-time visitor tell what to do next, and does that action work?
Owneralso link-integrity - 20
FAQ / help content
Are the questions this product predictably raises answered somewhere findable?
Owneralso content-trust, public-support - 21
Custom 404 with recovery
Does an unknown URL return a real 404 in the product's design, with a way back?
Owneralso design-system-reconnaissance - 22
Broken internal / external links
Does every nav, footer, CTA, and content link resolve?
Owneralso seo-readiness - 23
Dead buttons, fake controls, placeholders
Does every control do something real, and is unfinished UI gone?
Owneralso link-integrity, forms-readiness - 24
Loading, empty, success, failure, recovery states
Does the UI behave sensibly when data is slow, empty, or failing?
Owneralso forms-readiness - 25
Contact / support path
Is there a working way to reach a human, matching what the site promises?
Owneralso content-trust - 26
Claims, metrics, testimonials, social proof
Is every number, logo, quote, and badge real, sourced, and not misleading?
Owneralso policy-consistency
D Accessibility and responsive quality via
- 27
Image alt text / non-text alternatives
Does every meaningful image, icon, chart, and media item have a useful alternative?
Owner - 28
Semantic structure / headings
Do landmarks, headings, lists, and buttons use the right elements?
Owner - 29
Keyboard navigation / visible focus
Can everything be used with a keyboard, with a visible focus indicator?
Owneralso mobile-readiness - 30
Form labels, instructions, accessible errors
Are fields labeled, instructions clear, and errors announced and associated?
Owneralso wcag-readiness - 31
Contrast / readability
Is text legible against its background, at sensible size and line length?
Owner - 32
Reduced motion
Does motion respect prefers-reduced-motion and avoid seizure-risk patterns?
Owner - 33
Mobile / responsive behavior
Does the real site work at phone and tablet sizes, not just avoid a scrollbar?
Owneralso design-system-reconnaissance - 34
Mobile overflow, tables, dialogs, touch targets, sticky UI
Do wide content, modals, tap targets, and fixed bars behave on small screens?
Owneralso wcag-readiness
E Forms, communications, security, and performance via
- 35
Forms actually submit and handle outcomes
Does each form deliver data to a working endpoint and handle success and failure?
Owneralso failure-resilience - 36
Unsubscribe works where marketing email exists
Does the unsubscribe link/route/header resolve and complete?
Owner - 37
Unsubscribe results in suppression
After unsubscribing, is the address actually excluded from future marketing sends?
Owneralso data-rights - 38
Exposed secrets, client env mistakes, debug artifacts
Is any credential, private key, debug route, or source map exposed to visitors?
Owneralso deployment-cleanup, ai-features-readiness - 39
HTTPS / security headers / CSP / production sanity
Is transport secure and are headers and CSP sensible for what this site loads?
Owneralso web-security, dependency-security - 40
Performance
Are there oversized assets, blocking resources, font/image waste, or obvious bloat?
Owneralso mobile-readiness
A second, conditional layer run through . These domains describe the compliance areas ReadyVibe can inspect. During a real review, project evidence determines which areas need work and which questions require human review. Nothing here is legal advice.
- 01
Jurisdiction / market applicability
Where do users and the business operate, and which rule sets *may* matter?
Scope Always considered; it feeds every other domain
Escalates to a human when Markets are unclear, or several regimes may apply. Rules are never supplied from memory
Owner - 02
Privacy disclosure vs actual data behavior
What is collected, why, where does it go, and does the notice match?
Scope Any personal data is collected, stored, or transmitted
Escalates to a human when A required fact is missing (controller identity, retention, legal basis) or a disclosure contradicts behavior
Owner - 03
Cookies / trackers / consent
What stores or loads, and do reject / accept / withdraw work where consent is applicable?
Scope Any cookie, storage key, or third-party tracker is observed or source-indicated
Escalates to a human when Applicability of consent depends on a rule not yet looked up at an official source, or runtime proof is unavailable
Owner - 04
Marketing communications
Consent, sender identity, unsubscribe, suppression, preferences
Scope The product sends or plans to send marketing or newsletter email
Escalates to a human when Consent basis or jurisdiction-specific sender rules are unclear
Owner - 05
Age / children / minors
Audience, age collection, parental handling
Scope The audience may include minors, or age/DOB is collected, or content targets young users
Escalates to a human when Any child-directed signal. A decorative age gate is not a control
Owner - 06
User privacy rights
Access, correction, deletion, export, objection / opt-out
Scope Accounts exist, or personal data is stored, or the notice promises rights
Escalates to a human when Legal timelines, identity verification, or retention duties are unspecified
Owner - 07
E-commerce / consumer protection
Pricing, subscriptions, cancellation, refunds, recurring billing, merchant identity
Scope Money changes hands, or an offer/price/subscription is shown
Escalates to a human when Refund, withdrawal, auto-renewal, or tax wording is jurisdiction-specific and not source-backed
Owner - 08
Accessibility obligations
Where accessibility may carry legal weight, beyond good UX
Scope Public-facing product, commerce, public-sector, or education audience
Escalates to a human when Always as REVIEW REQUIRED for legal significance. A scan cannot establish conformance
Owner - 09
Third-party vendors / data sharing
Analytics, payment processors, embeds, external services, transfers
Scope Any third-party host is contacted or a vendor SDK is present
Escalates to a human when Cross-border transfer, processor terms, or sensitive data reach a vendor
Owner - 10
Security / production obligations
Exposed secrets, account handling, disclosures, applicable security requirements
Scope Always considered for a deployed product
Escalates to a human when A credential leaked, a breach is suspected, or a sector security standard may apply
Owner - 11
Regulated-domain triggers
Health, finance, education, children, legal, crypto, gambling, and similar
Scope Product language, data fields, or features touch a regulated domain
Escalates to a human when Always. These stop being "ordinary web rules" and need specialist review
Owner - 12
Legal identity / IP / required notices
Company and contact disclosures, copyright, trademark, licensing, attribution
Scope Any public product; deeper if commerce, user content, or third-party assets exist
Escalates to a human when Operator identity, registered address, or license obligations are unknown
Owner