Quality assurance + vulnerability checks before scale. Agent charter: .cursor/autopilot/qavapt.md · checklist: docs/QA_VAPT_CHECKLIST.md (repo).
./scripts/security-smoke.sh: client secret hygiene, IPN gate, admin RPC auth./tests/e2e_smoke.sh: build + auth modules + worker compile./scripts/verify-activation-path.sh: after P0 green./scripts/check-plan-intent.sh · ./scripts/check-seo-content.sh: production funnel/SEO./scripts/verify-activation-path.sh --partial: signup → deploy (no worker)./scripts/guide-partial-e2e.sh: founder manual partial E2E steps./scripts/check-parallel-growth.sh · ./scripts/check-sales-ready.sh./scripts/check-qa-parallel.sh: security + XSS + partial activation + sales (worker blocked)./scripts/check-xss-hygiene.sh: /app esc() patterns./scripts/guide-qa-founder-standup.sh: combined parallel QA playbook./scripts/guide-founder-growth-standup.sh: all role standups combined · quick: ZT_QUICK_GROWTH_STANDUP=1./scripts/guide-founder-parallel.sh: all parallel playbooksProbing production IPN gate…
Automated QA you can run now (no trades required):
./scripts/security-smoke.sh: secrets, IPN gate, RLS anon probes./scripts/verify-activation-path.sh --partial: signup → deploy funnel./scripts/guide-partial-e2e.sh: manual steps 1–2 · View evidence → /app#forward./scripts/check-free-tier-limit.sh · ./scripts/guide-free-tier-test.sh: Q9 second deploy blocked./scripts/check-founder-parallel-ready.sh: all parallel probes in one command./scripts/guide-qa-rls-isolation.sh: post-P0 manual RLS isolation (Q3)./scripts/check-xss-hygiene.sh: /app XSS hygieneTrust path before checkout: deploy → View evidence → /app#forward · Index: docs/FOUNDER_PARALLEL.md · ./scripts/check-growth-goal.sh
docs/QA_VAPT_CHECKLIST.md: mark Q1–V3