NEW v0.2.0 · store privacy forms, SDK upgrades, audit history

Ship Expo apps that are fast, secure and store-ready.

A Claude Code plugin that audits your Expo & React Native app with a team of specialist agents, scores it 0–10 across 13 categories, fixes what it finds and proves the fixes work.

/plugin marketplace add eusebiu-soica/expo-es-kit
MIT licensed Zero-dependency local scanner Never prints your secrets

Built for the stack you already use

Expo SDK 54+React Native 0.81+expo-routerSupabaseNext.js on VercelMMKVTanStack QueryHeroUI Native

The problem

Agents write code fast.
They forget the rules that matter.

The slips that make a mobile app slow or unsafe are rarely in the happy path. expo-es-kit gives Claude Code those rules, and checks that they are followed.

A session token ends up in AsyncStorage
Tokens in SecureStore, everything else in encrypted MMKV
2,000 rows rendered inside a ScrollView
Virtualized lists, memoized rows, measured on min-spec Android
A full-size photo decoded for a 60 px thumbnail
Transformed thumbnails, expo-image with a disk cache
Sign-out leaves the last user's data in the cache
Server-side revoke plus a full wipe of queries, MMKV and images

Features

Everything between “it runs” and “it ships”

Nine skills, nine agents and a real-time guard, all working from one shared scoring contract.

Scored audits with a verdict

13 categories (14 with HeroUI Native), each scored 0–10 with file:line evidence for every finding, a GO / NO-GO verdict and a trend against your last audit.

Deep multi-agent mode

8 specialist auditors run in parallel. An adversarial verifier then tries to disprove every serious finding.

Fixes that prove themselves

Every fix run ends with gates, an independent re-check per finding, a regression scan and a before/after table.

Agent rules per folder

Short CLAUDE.md files for components, lib, storage, routes, migrations… and detection of stale rules you already have.

Backend & sessions included

Supabase direct-DB (RLS, policies, definer functions) or your own API on Next.js, Supabase Edge Functions or Expo API Routes.

A proven foundation

Encrypted MMKV, a SecureStore session adapter, an API client with single-flight refresh, per-family query snapshots, a complete sign-out wipe and env validation, adapted to your app.

app-storageapi-clientquery-clientsign-outenverror-boundary

Store privacy forms from evidence

Draft answers for App Store App Privacy and Google Play Data safety, plus a privacy manifest check, built from your SDKs, permissions, code and database schema.

35+ SDKspermissionsDB schemarequired-reason APIs

Safe SDK upgrades

One major at a time, with gates and a device smoke test after every step.

Audit history & badge

An offline HTML dashboard of scores over time, and a score badge for your README.

Real-time guard & HeroUI

A warn-only hook flags dangerous code as soon as it is written. HeroUI Native gets its own audit for imports, sheets, tokens and animations.

How deep mode works

Signals, specialists, then a skeptic

A scan hit is a signal, not a finding. Every finding needs code an agent actually read, and every serious one has to survive a verifier whose only job is to disprove it.

01 · LOCAL

scan.mjs

Zero-dependency static scan: stack, config, env key names (never values), migrations and RLS, API routes, 120+ rules with file:line.

02 · PARALLEL

8 specialist auditors

perfbundle-deps storage-cacheclient-security auth-sessionbackend releaseheroui
03 · ADVERSARIAL

finding-verifier

Re-reads the code behind every P0/P1 and looks for wrappers, middleware or later migrations that mitigate it.

confirmeddowngradedrejected
04 · REPORT

Score & verdict

Weighted overall score, trend ▲▼ vs the last run, Top 10 fixes, and “what was not checked”. Saved as Markdown + JSON.

GOGO WITH RISKSNO-GO

Scoring

One contract, every skill

The same IDs, severities, caps and JSON shapes across audit, fix, backend and history. That is what makes trends and verified fixes possible.

Rules

SeverityP0 exploitable hole, data leak, crash on start or store rejection. P1 significant issue. P2 hygiene.
CapsA confirmed P0 caps its category at 4. A confirmed P1 caps it at 7.
OverallWeighted average. Security categories count 1.5×.
VerdictNO-GO any confirmed P0 · GO WITH RISKS a security P1 or overall below 7 · GO otherwise

Categories

Performanceperf1.0
Startup speedstartup1.0
Bundle sizebundle1.0
Cachingcaching1.0
MMKVmmkv1.0
Secure storagesecure-storage1.5
Client securityclient-security1.5
Auth & sessionsauth-sessions1.5
Backend securitybackend1.5
Dependenciesdeps1.0
Updatesupdates1.0
Release readinessrelease1.0
Agent instructionsagent-config0.5
HeroUI Nativeheroui · if installed1.0

Commands

Nine skills. Ask in plain words or by name.

“Audit my app before release”, “is my API secure?”, “set up CLAUDE.md files” all work. Every command that writes shows a plan and diffs first, and never overwrites your files.

Audit

Scored production-readiness audit. Read-only.

/expo-es-kit:audit [appPath] [--quick | --deep] [--api=<apiRepoPath>] [--only=<ids>]
  • Quick: one agent, a static scan and targeted reads. About 5–15 minutes. Good for weekly checks.
  • Deep: 8 specialists in parallel, then a verifier. Use it before releases.
  • --api=../my-api also audits a separate backend repo, e.g. a Next.js project on Vercel.
  • Saves docs/audits/expo-audit-YYYY-MM-DD.md + .json. The report follows your language.
Writes code: never, report only

Verified fixes

“Done” means verified.

The fix skill never reports “all fixed” unless every finding is confirmed by an independent verifier and every gate is green. Gates it could not run are reported as “not run”, never as passed.

  1. Baseline. Fresh scan and gates before touching anything.
  2. Apply. Minimal diffs in batches you confirm, P0 first.
  3. Verify. Gates, verifier per finding, regression scan, re-audit.
  4. Report. Before/after scores and the new verdict.
Fix report docs/audits/expo-fix-2026-10-07.md
CategoryBeforeAfterΔFixedOpen
Auth & sessions7.09.0+2.020
Release3.07.5+4.521
Client security6.58.5+2.030
typecheck lint tests 142/142 expo-doctor rebuild required GO WITH RISKS
lib/auth/session.ts
import AsyncStorage from '@react-native-async-storage/async-storage';

export async function saveSession(session) {
  await AsyncStorage.setItem('access_token', session.access_token);
}
⚠ expo-es-kit guard · P0
Token written to AsyncStorage (unencrypted). Store session tokens in expo-secure-store.

Guard hook

Caught while it's being written.

After every Write or Edit in an Expo project, a fast local check scans only the text just written. The agent gets a warning and corrects itself. It never blocks an edit.

Tokens or passwords in AsyncStorageP0
service_role or secret-looking EXPO_PUBLIC_*P0
Hard-coded Stripe, AWS, GitHub or Supabase secretsP0
Tokens in logs or URLs, cleartext http://P1
Whole-cache persistence, full lodash, RN Image for remoteP2

Compared

Complements the official skills

The official expo/skills teach how to use Expo APIs. expo-es-kit checks that the result is production-ready.

expo/skillsRN review skillsexpo-es-kit
How to use Expo APIs✓–complements
Scored audit + verdict✕checklist✓
Verification pass against false positives✕✕✓
Trend across audits✕✕✓
MMKV, secure storage, sessions✕partial✓
Backend: RLS and API security✕✕✓
Applies fixes and re-verifies✕✕✓
Per-folder agent rules✕✕✓
Store privacy forms from code evidence✕✕✓
SDK upgrade with gates per step✓✕✓
Score history + badge✕✕✓

Workflows

From the first commit to every release

New app

Start with the right structure.

  1. /expo-es-kit:backend designpick direct-db, api or hybrid
  2. /expo-es-kit:foundationcore modules
  3. /expo-es-kit:setupagent rules for every folder

Every week

The guard runs on its own.

  1. /expo-es-kit:audit --quickscores and trend
  2. /expo-es-kit:fix --only=P0blockers first

Before a release

Go deep, then prove it.

  1. /expo-es-kit:audit --deep --api=../my-api
  2. /expo-es-kit:fix --only=P0,P1
  3. /expo-es-kit:privacystore answers + manifest
  4. /expo-es-kit:historydashboard + badge

SDK behind

When the audit flags updates.

  1. /expo-es-kit:upgrade --plan-onlyreview the plan
  2. /expo-es-kit:upgradeone verified major at a time

Install

Up and running in a minute

Run these inside Claude Code. Restart it if the commands don't appear, then check /plugin.

STEP 1

Add the marketplace

Install the plugin from GitHub.

claude code
/plugin marketplace add eusebiu-soica/expo-es-kit
/plugin install expo-es-kit@expo-es-kit
STEP 2

Run your first audit

From your Expo app's folder.

claude code
/expo-es-kit:audit --quick
STEP 3

Fix the blockers

Then watch the trend go up.

claude code
/expo-es-kit:fix --only=P0
Claude Code with plugin support Node.js 18+ Expo app, tested on SDK 54+ Optional: git, Supabase MCP

Safety

Careful with your code and your secrets

Audits are read-only

They never edit code and never run npm install, expo prebuild or expo export.

Secrets stay secret

Only env key names are read, never values. Secret-looking literals are redacted in every output.

No silent overwrites

Every write is preceded by a plan, diffs and your confirmation.

CLI checks are opt-in

You are asked before expo-doctor, npm audit and similar commands run.

Installs stay yours

Dependency commands are printed for you to run on the OS you use, so WSL never breaks your node_modules.

Remote systems untouched

Never applies migrations, never probes production, never touches remote databases.

FAQ

Questions, answered

Quick or deep: which should I run?

Quick is a single agent. It is cheap, takes about 5–15 minutes and suits weekly checks; its findings are not independently verified. Deep runs 8 specialists plus a verifier. It is thorough but uses many more tokens, so run it before releases or after big changes.

Does it work without Supabase, HeroUI or MMKV?

Yes. Categories adapt to what is installed and become n/a when they don't apply. The MMKV category, for example, scores whether your app would need it.

My backend lives in another repo.

Pass it with --api=../my-api on audit, setup or backend. Without it, the kit notices sibling folders that look like an API and asks whether to include them.

A finding is wrong, or my code does it on purpose.

Write the decision down in your docs or CLAUDE.md, ideally with the measurement behind it. Auditors respect documented, measured trade-offs, and the verifier rejects findings mitigated elsewhere.

Are the privacy answers legal advice?

No. They are draft answers based on what your code shows, with evidence for every “collected” item. You remain responsible for the final declarations.

Monorepo?

Point appPath at the Expo app (apps/mobile) and --api at the backend (apps/api).

The commands don't show up after installing.

Restart Claude Code, run /plugin and check that expo-es-kit is enabled. For local development use claude --plugin-dir /path/to/expo-es-kit.

Open source · MIT

Give your agents the rules.
Ship with a verdict.

Install in a minute, run your first audit, and know exactly what stands between your app and the store.