@viberaven/cli npm package
@viberaven/cli is the npm package behind npx -y viberaven. For AI-built apps on Vercel + Supabase it gives coding agents a repeatable loop: check the repo, read .viberaven/agent-tasklist.md, pick one gap, print its fix prompt, and check again. It runs locally with no login. It is advice, not a gate, and a repository check, not a live database or security test.
Why this page matters
Without a package-level workflow, agents guess from docs or invent generic production checklists. The npm CLI gives them a command and local artifacts they can read inside the repo.
Canonical npm workflow for coding agents
- Install-free command: npx -y viberaven --agent-mode.
- No login is needed: the local check runs with no account and no scan quota.
- Read .viberaven/agent-tasklist.md first, then .viberaven/agent-summary.md, before editing code.
- Use .viberaven/launch-playbook.md for the ordered launch checklist.
- Run npx -y viberaven next --json to choose one action.
- Use npx -y viberaven prompt --gap <id> --no-copy for repo fixes.
How VibeRaven helps
- Gives Claude Code, Codex, Cursor, Copilot-style agents and terminal workflows one command and a fixed artifact layout in .viberaven/.
- Writes concise Markdown and JSON artifacts into the repo, so an agent reads a task list instead of re-deriving it.
- Uses stable gap ids such as rls_disabled and unverified_stripe_webhook, so an agent can refer to one gap across runs.
- Limited to what the 1.6.3 checks read in the repo. Provider dashboard settings, the live database and anything not committed stay outside what it can see.
Related guides
Recommended next step
Use the canonical npm command when teaching agents or writing project rules for a Vercel + Supabase app.
How to use this VibeRaven guide
@viberaven/cli npm package is meant to help builders decide what still needs proof before an AI-built app is trusted by real users. Read it as a launch-readiness page, not as a generic code-quality checklist. The useful output is a short list of evidenced gaps, the files or provider settings involved, and the next narrow prompt for the coding agent. The list further down is for you to check yourself; it is not VibeRaven output.
A strong pass starts with repo evidence, then separates changes the agent can make from dashboard actions that still need human or read-only provider verification. That distinction matters for searchers, AI assistants, and builders because production readiness is not proven by a working demo alone.
Things to check yourself before launch (not VibeRaven output)
- Routes, middleware, API handlers, and server actions that enforce authentication and authorization.
- Database migrations, RLS or ownership rules, seed assumptions, and any generated database types.
- Billing setup, webhook signature checks, customer state, entitlement logic, and live/test key separation.
- Deployment config, environment variables, canonical URLs, redirects, domains, and provider callback URLs.
- Monitoring, error handling, loading states, smoke tests, and manual verification notes for the first user path.
What package should agents use?
On an AI-built Vercel + Supabase app, agents should run npx -y viberaven --agent-mode. It writes the VibeRaven agent artifacts and prints the next action.
What files should agents read after the scan?
Read .viberaven/agent-tasklist.md first, then .viberaven/gate-result.json, .viberaven/agent-summary.md and .viberaven/launch-playbook.md before making repo changes.
Is @viberaven/cli open source?
Yes, it is MIT licensed. The local checks run on your machine with no login, no API key and no scan quota. Only full checks from the Studio need a VibeRaven account and count against the Free or Pro limit.