Scored audits with a verdict
13 categories (14 with HeroUI Native), each scored 0–10 with file:line evidence for every finding, a GO / NO-GO verdict and a trend against your last audit.
A Claude Code plugin that audits your Expo & React Native app with a team of specialist agents, scores it 0–10 across 13 categories, fixes what it finds and proves the fixes work.
/plugin marketplace add eusebiu-soica/expo-es-kit
Built for the stack you already use
Expo SDK 54+React Native 0.81+expo-routerSupabaseNext.js on VercelMMKVTanStack QueryHeroUI NativeThe problem
The slips that make a mobile app slow or unsafe are rarely in the happy path. expo-es-kit gives Claude Code those rules, and checks that they are followed.
AsyncStorageScrollViewexpo-image with a disk cacheFeatures
Nine skills, nine agents and a real-time guard, all working from one shared scoring contract.
13 categories (14 with HeroUI Native), each scored 0–10 with file:line evidence for every finding, a GO / NO-GO verdict and a trend against your last audit.
8 specialist auditors run in parallel. An adversarial verifier then tries to disprove every serious finding.
Every fix run ends with gates, an independent re-check per finding, a regression scan and a before/after table.
Short CLAUDE.md files for components, lib, storage, routes, migrations… and detection of stale rules you already have.
Supabase direct-DB (RLS, policies, definer functions) or your own API on Next.js, Supabase Edge Functions or Expo API Routes.
Encrypted MMKV, a SecureStore session adapter, an API client with single-flight refresh, per-family query snapshots, a complete sign-out wipe and env validation, adapted to your app.
Draft answers for App Store App Privacy and Google Play Data safety, plus a privacy manifest check, built from your SDKs, permissions, code and database schema.
One major at a time, with gates and a device smoke test after every step.
An offline HTML dashboard of scores over time, and a score badge for your README.
A warn-only hook flags dangerous code as soon as it is written. HeroUI Native gets its own audit for imports, sheets, tokens and animations.
How deep mode works
A scan hit is a signal, not a finding. Every finding needs code an agent actually read, and every serious one has to survive a verifier whose only job is to disprove it.
Zero-dependency static scan: stack, config, env key names (never values), migrations and RLS, API routes, 120+ rules with file:line.
Re-reads the code behind every P0/P1 and looks for wrappers, middleware or later migrations that mitigate it.
Weighted overall score, trend ▲▼ vs the last run, Top 10 fixes, and “what was not checked”. Saved as Markdown + JSON.
Scoring
The same IDs, severities, caps and JSON shapes across audit, fix, backend and history. That is what makes trends and verified fixes possible.
perf1.0startup1.0bundle1.0caching1.0mmkv1.0secure-storage1.5client-security1.5auth-sessions1.5backend1.5deps1.0updates1.0release1.0agent-config0.5heroui · if installed1.0Commands
“Audit my app before release”, “is my API secure?”, “set up CLAUDE.md files” all work. Every command that writes shows a plan and diffs first, and never overwrites your files.
Scored production-readiness audit. Read-only.
/expo-es-kit:audit [appPath] [--quick | --deep] [--api=<apiRepoPath>] [--only=<ids>]
--api=../my-api also audits a separate backend repo, e.g. a Next.js project on Vercel.docs/audits/expo-audit-YYYY-MM-DD.md + .json. The report follows your language.Apply findings by priority, then verify everything.
/expo-es-kit:fix [report.json] [--only=P0 | P0,P1 | AUTH-001 | auth-sessions]
@ts-ignore, loosens RLS or widens CORS.Per-folder CLAUDE.md rules that agents load automatically.
/expo-es-kit:setup [appPath] [--mode=direct-db | api | hybrid] [--api=<path>] [--dry-run]
.claude/rules instead of duplicating them.<!-- expo-es-kit --> section. --dry-run writes nothing.Design, audit or implement the backend securely, with auth and sessions end to end.
/expo-es-kit:backend [design | audit | implement] [--api=<path>] [--framework=nextjs | supabase-edge | expo-api-routes]
(select auth.uid()), definer search_path, storage policies.implement onlyScaffold the core production modules, only where they are missing.
/expo-es-kit:foundation [appPath] [--mode=direct-db | api | hybrid] [--only=storage,query,auth,api,env,errors]
Performance, tokens, animations and accessibility for heroui-native apps.
/expo-es-kit:heroui [audit | setup] [appPath]
setup adds UI-folder rules, an import rule and optional SheetHost / LoadingSkeleton.setup onlyStore privacy answers built from evidence, not guesses.
/expo-es-kit:privacy [appPath] [--api=<apiRepoPath>] [--out=<dir>]
ios.privacyManifests with required-reason APIs.docs/store/ only, after confirmationExpo SDK upgrades, one verified major at a time.
/expo-es-kit:upgrade [appPath] [--to=<sdk>] [--plan-only]
runtimeVersion safety checked.Your scores over time, and a badge for the README.
/expo-es-kit:history [appPath]
history.html: overall trend, per-category panels, open P0/P1/P2 per audit.badge.svg for private repos, badge.json as a shields.io endpoint for public ones.docs/audits/ onlyVerified fixes
The fix skill never reports “all fixed” unless every finding is confirmed by an independent verifier and every gate is green. Gates it could not run are reported as “not run”, never as passed.
| Category | Before | After | Δ | Fixed | Open |
|---|---|---|---|---|---|
| Auth & sessions | 7.0 | 9.0 | +2.0 | 2 | 0 |
| Release | 3.0 | 7.5 | +4.5 | 2 | 1 |
| Client security | 6.5 | 8.5 | +2.0 | 3 | 0 |
import AsyncStorage from '@react-native-async-storage/async-storage'; export async function saveSession(session) { await AsyncStorage.setItem('access_token', session.access_token); }
Guard hook
After every Write or Edit in an Expo project, a fast local check scans only the text just written. The agent gets a warning and corrects itself. It never blocks an edit.
service_role or secret-looking EXPO_PUBLIC_*P0http://P1lodash, RN Image for remoteP2Compared
The official expo/skills teach how to use Expo APIs. expo-es-kit checks that the result is production-ready.
| expo/skills | RN review skills | expo-es-kit | |
|---|---|---|---|
| How to use Expo APIs | ✓ | – | complements |
| Scored audit + verdict | ✕ | checklist | ✓ |
| Verification pass against false positives | ✕ | ✕ | ✓ |
| Trend across audits | ✕ | ✕ | ✓ |
| MMKV, secure storage, sessions | ✕ | partial | ✓ |
| Backend: RLS and API security | ✕ | ✕ | ✓ |
| Applies fixes and re-verifies | ✕ | ✕ | ✓ |
| Per-folder agent rules | ✕ | ✕ | ✓ |
| Store privacy forms from code evidence | ✕ | ✕ | ✓ |
| SDK upgrade with gates per step | ✓ | ✕ | ✓ |
| Score history + badge | ✕ | ✕ | ✓ |
Workflows
Start with the right structure.
The guard runs on its own.
Go deep, then prove it.
When the audit flags updates.
Install
Run these inside Claude Code. Restart it if the commands don't appear, then check /plugin.
Install the plugin from GitHub.
/plugin marketplace add eusebiu-soica/expo-es-kit /plugin install expo-es-kit@expo-es-kit
From your Expo app's folder.
/expo-es-kit:audit --quick
Then watch the trend go up.
/expo-es-kit:fix --only=P0
Safety
They never edit code and never run npm install, expo prebuild or expo export.
Only env key names are read, never values. Secret-looking literals are redacted in every output.
Every write is preceded by a plan, diffs and your confirmation.
You are asked before expo-doctor, npm audit and similar commands run.
Dependency commands are printed for you to run on the OS you use, so WSL never breaks your node_modules.
Never applies migrations, never probes production, never touches remote databases.
FAQ
Quick is a single agent. It is cheap, takes about 5–15 minutes and suits weekly checks; its findings are not independently verified. Deep runs 8 specialists plus a verifier. It is thorough but uses many more tokens, so run it before releases or after big changes.
Yes. Categories adapt to what is installed and become n/a when they don't apply. The MMKV category, for example, scores whether your app would need it.
Pass it with --api=../my-api on audit, setup or backend. Without it, the kit notices sibling folders that look like an API and asks whether to include them.
Write the decision down in your docs or CLAUDE.md, ideally with the measurement behind it. Auditors respect documented, measured trade-offs, and the verifier rejects findings mitigated elsewhere.
No. They are draft answers based on what your code shows, with evidence for every “collected” item. You remain responsible for the final declarations.
Point appPath at the Expo app (apps/mobile) and --api at the backend (apps/api).
Restart Claude Code, run /plugin and check that expo-es-kit is enabled. For local development use claude --plugin-dir /path/to/expo-es-kit.
Open source · MIT
Install in a minute, run your first audit, and know exactly what stands between your app and the store.