audit-infra
Infrastructure-first security audit — secrets, supply chain, CI/CD, LLM/skill security, OWASP, STRIDE. Complements /audit-solana (program-level)
Product quality review — first-time-user walkthrough, 8-dimension scorecard, prioritized fix roadmap. --harsh for the brutal roast variant
> /plugin marketplace add solanabr/solana-ai-kit > /plugin install solana-ai-kit@stbr
How it fires
How this command gets triggered: by you, by Claude, or both.
/product-reviewContext preview
What this command does when you run it.
Product quality review — first-time-user walkthrough, 8-dimension scorecard, prioritized fix roadmap. --harsh for the brutal roast variant
description: "Product quality review — first-time-user walkthrough, 8-dimension scorecard, prioritized fix roadmap. --harsh for the brutal roast variant"
<!-- Adapted from product-review + roast-my-product (sendaifun/solana-new), MIT © 2026 SendAI and Superteam. Telemetry removed. -->
You are reviewing a product the way its next user will experience it — not the way its builder hopes it works. Default mode is balanced and structured; `--harsh` is a stress test.
| Invocation | Tone | Output contract | |------------|------|-----------------| | `/product-review` | Balanced, constructive | 8-dimension scorecard + bucketed roadmap | | `/product-review --harsh` | Brutal but constructive | 10 weighted dimensions + verdict + exactly 3 fixes |
This is not a code review — route code quality to `/diff-review` and security to `/audit-solana` / `/audit-infra`.
Ask before reviewing — never assume:
If no product exists yet, stop and suggest `/plan-feature` or `/scaffold` instead.
Become the target user from Step 1. If a URL or local build is available, **offer to drive it live with the playwright MCP** (`browser_navigate` → `browser_snapshot` → click through the core flow); otherwise walk the screens/code. Record an observation per checkpoint:
Document every friction point with where it happens and what the user sees.
Score each 1–10. Every score requires evidence from Step 2 — "onboarding 6/10 because step 3 demands a wallet without explaining why" — never a bare number.
| # | Dimension | What you're judging | |---|-----------|---------------------| | 1 | Onboarding | Landing → first meaningful action: steps, friction, wallet deferral | | 2 | Core-loop clarity | Is the repeated action obvious? Is there a reason to come back? | | 3 | Empty states | Zero-balance, no-history, no-results screens guide instead of confuse | | 4 | Error states | Tx failures human-readable, recovery guidance, no silent failures | | 5 | Performance | Load time, tx feedback latency, informative loading states, data freshness | | 6 | Trust signals | Audits, team, volume, social proof, comprehensible approval dialogs | | 7 | Mobile | Responsive layout, touch targets, wallet deep-linking | | 8 | Docs | Can a user self-serve answers? README/help/FAQ accuracy |
Overall = average, one decimal. For each dimension note: working well / needs improvement / one concrete fix for the biggest issue.
Bucket every fix, ordered by impact within each bucket:
Distinguish "nice to have" from "users are bouncing here" — the roadmap leads with the latter.
## Executive Summary [2-3 sentences: overall quality, biggest strength, biggest risk] ## Scorecard | Dimension | Score | Evidence | |-----------|-------|----------| | Onboarding | x/10 | ... | | ... (all 8) | | | | **Overall** | **x/10** | | ## Top 3 Strengths 1. [Strength] — [specific evidence] ## Top 3 Improvements 1. [Change] — [expected impact] ## Roadmap ### Quick wins (< 1 day) - [ ] [Fix] — [impact] ### Medium (1–3 days) - [ ] ... ### Major (1 week+) - [ ] ...
---
A stress test, not a review. Find every weakness before users and investors do.
| # | Dimension | Weight | Kill question | |---|-----------|--------|---------------| | 1 | Value proposition | **2x** | Explain it in one sentence without "decentralized/protocol/ecosystem" — can you? | | 2 | Crypto necessity | 1x | What breaks if the chain becomes a database? Nothing → 1–3 | | 3 | Target user clarity | 1x | Could you DM 10 real target users on Twitter right now? | | 4 | First-time UX | 1x | Wallet-gate before any value shown? Jargon wall? | | 5 | Core loop | 1x | What triggers a day-7 return? No answer → no loop | | 6 | Moat | 1x | A funded competitor clones this in a weekend — what saves you? | | 7 | Technical execution | 1x | What happens when the RPC dies mid-transaction? | | 8 | Naming & messaging | 1x | Heard once — can you spell it and repeat the pitch? | | 9 | Monetization | 1x | Token goes to zero — does the business survive? | | 10 | Market timing | 1x | Why now? What changed in the last 6 months? |
Weighted total /110: 90+ exceptional · 70–89 strong · 50–
Production-ready Claude Code configuration for full-stack Solana development. Combines best practices from multiple sources into an agent-optimized, token-efficient config you can install and adapt to your specific project.
Repo: solanabr/solana-ai-kit
Infrastructure-first security audit — secrets, supply chain, CI/CD, LLM/skill security, OWASP, STRIDE. Complements /audit-solana (program-level)
Benchmark CU usage and compare against baseline for regression detection