Mobile Starter Kit

Accessibility, performance, and security audits

Three evidence-based reviews your coding agent can run against the real app.

Run audits on a production-like build after the main product shape is stable and again before release. Ask for findings with evidence, not a generic checklist.

Accessibility

Read agent-skills/a11y-audit.md. Audit every primary path with VoiceOver and
TalkBack, large and bold text, both themes, reduced motion, keyboard focus on
web, and 48dp targets. Report severity, screen, platform, reproduction, expected
behavior, and proposed fix. Re-test critical and high issues on device.

Pay special attention to charts, camera state, live Coach responses, unread notifications, dialogs/sheets, errors, offline announcements, and focus order.

Performance

Read agent-skills/perf-audit.md. Measure a production-like build before changing
code. Profile cold/warm startup, tab switches, Coach first token, Scan analysis,
repeated photos, lists, query behavior, memory, animation, and battery. Return
baseline, device/build, evidence, change, and post-change result.

Development mode timings are not release performance evidence.

Security

Read agent-skills/security-review.md. Threat-model identity, RLS, private uploads,
AI and webhook secrets, deep-link inputs, deletion, analytics/error payloads,
local storage, and release configuration. Prove critical boundaries with tests
or provider evidence. Do not paste secrets into the report.

Check the app bundle and logs for server secrets, signed URLs, tokens, email, prompts, images, voice files, and sensitive nutrition data. A passing linter is not proof that provider configuration or store declarations are correct.

On this page