Skip to content

Not verified

AI feature controls

Whether prompts, spend, and model output are bounded so one visitor cannot run up the bill.

Last updated September 20, 2026

Needs the code

Why a check from outside cannot see it

Prompt handling, spend limits and output checks happen inside a server call. From outside, a model that costs a tenth of a cent and one that costs a dollar look identical.

How to check it yourself

  1. 1Send your longest plausible input to the AI feature twenty times in a row.
  2. 2Watch the provider spend for that hour, then multiply by a bored stranger.
  3. 3Paste an instruction inside the content itself and see whether the model follows it.

Send a long input to your AI feature repeatedly and watch the provider spend for the hour.

What a Launch Review does instead

Launch Review, $199

A reviewer sends long and hostile inputs, watches spend for the hour, and reads how model output is used.

See what a Launch Review covers

Incidents that involved this

  • Not verified

    OpenClaw CVE-2026-31992

    An allowlist bypass scored 9.9 on CVSS and was described as a full guardrail bypass.

See all nine items

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026