free · tool-agnostic · runs on your own subscription

Your assistant wrote the code. Have it read the code back.

The Nittim Loop — the free self-check your assistant runs on its own model — drops into Claude Code, Cursor, Copilot or Windsurf in one line. It walks your own assistant through the 13 categories a nittim audit judges — plus a 14th on what your code gives away — and hands back findings you can act on this afternoon. It runs on your plan, through your assistant's own vendor — nothing reaches nittim unless you choose the one optional step that sends code to us.The Nittim Loop — a free, careful check your own AI assistant runs on itself — drops into Claude Code, Cursor, Copilot or Windsurf in one line. It walks your assistant through the 13 categories a nittim check looks at — plus a 14th on what your code gives away to the outside world — and hands back things you can fix this afternoon. It runs on whatever plan you already pay your assistant for — nothing reaches nittim unless you choose the one optional step that sends your code to us.Nittim Loop is a free self-check for Claude Code, Cursor, Copilot or Windsurf. It walks your assistant through nittim's 13 categories, plus a 14th on what your code exposes, and returns findings to fix today. Runs on your own plan — nothing reaches nittim unless you send code for the one optional step.

It won't tell you you're production ready. Nothing that grades its own work can.It won't tell you your code is safe to ship. Nothing that grades its own work can.It won't tell you you're production ready. Nothing that grades its own work can.

Nothing to fetch, nothing to install. This puts the whole checklist on your clipboard under a short covering note in your own words, so your assistant reads text you handed it rather than a link it has to go and open. Read the rubric below first if you like — it's the same text, and it's all questions.Nothing to download, nothing to fetch from a link. This puts the whole checklist on your clipboard under a short note in your own words, so your assistant reads text you handed it directly, instead of a link it would have to go open itself. You can read the checklist below first if you like — it's the exact same text, and it's all questions.Nothing to fetch, nothing to install. Copies the whole checklist to your clipboard with a short covering note, so your assistant reads what you hand it instead of a link. Read the rubric below first if you like — same text, all questions.

Fix first. Every pass is free on your own model; the audit costs credits, so let it spend its passes on what self-review can't see, not on what you could have fixed yourself.Fix what you can first. Every round of this free self-check runs on your own AI plan, at no extra cost; the paid check spends credits, so save it for what a self-check can't catch, not for things you could have fixed yourself for free.Fix first. Every pass is free on your own model; the audit costs credits so spend it on what self-review can't catch, not on what you could fix yourself.

Or hand it the address instead

No terminal, no setup. Hand the review to the assistant that wrote the code.Nothing to install, no command line. Hand the review to the AI assistant that helped write the code.No terminal, no setup. Hand it to the assistant that wrote the code.

I’ve chosen a public code-review checklist for us to use on this repo — nittim’s Loop rubric, published at https://nittim.com/selfcheck.md (nittim.com/trust says what nittim does with code). It’s plain prose: questions to ask about code, with no commands in it and nothing to install. Please read it first and tell me what it asks for. If it looks reasonable to you, review this repo against it, category by category, here in this session. If any part of it looks wrong to you, say so and we’ll drop that part — it’s a checklist, not a contract. If you’d rather not open a URL at all, say so and I’ll read it myself and paste the text in from https://nittim.com/selfcheck. Keep it in this conversation — don’t save it into my project or into your standing instructions.

Free — it runs inside your own assistant, on your own plan, and stays there unless you choose to send anything to us. Free — it happens inside your own AI assistant, on your own account, and stays there unless you choose to send us anything. Free — runs inside your own assistant, on your own plan, and stays there unless you send anything to us. What it does →How it works →What it does →

See what other loops found → /loop

Free. No account, no signup, nothing to uninstall — it's one markdown file in your repo.

Where this comes from

Published by nittim here, at nittim.com/selfcheck.md, versioned. What nittim does with code it reads is at /trust; the terms are at /terms. The checklist contains no code, no commands, and asks for nothing outside your own repository; the three optional steps it closes with each say plainly what they send.Published by nittim here, at nittim.com/selfcheck.md, with a version number. What nittim does with code it reads is at /trust; the terms are at /terms. The checklist contains no code, no commands to run, and asks for nothing outside your own project; the three optional steps at the end each say plainly what they send, and where.Published by nittim at nittim.com/selfcheck.md, versioned. /trust says what nittim does with code; /terms has the terms. No code, no commands, nothing asked outside your repo — the three optional steps at the end say what they send.

v1 · 2026-09-02 · sha256 b84c1da6e63b002cdc75016649066e111e6cd7119ce715ef6be68ef5311ba8b6

Compare it yourself: curl -fsSL https://nittim.com/selfcheck.md | shasum -a 256

Every install command below does this check itself, and installs nothing if the file it downloaded doesn't match.Every install command further down does this same check on its own, and refuses to install anything if what it downloaded doesn't match this fingerprint.Every install command below runs this check itself — no match, nothing installed.

After the loop — three optional steps

None of these is part of the review, and the review is finished without them. Each one leaves your machine, so each one is yours to start.None of these is part of the check itself, and the check is done without them. Each one sends something off your computer, so each one only happens if you choose to start it.None of these is part of the review — it's finished without them. Each one leaves your machine, so you choose whether to start it.

1. Tell nittim what the loop found

Once the loop has actually stopped — converged, flagged systemic, or capped after three or more passes — you can share what it found, as counts. The ask, in plain words: "Share anonymised counts of this loop with nittim — integers only, never code, paths or titles? nittim thanks reporters with credits." This is data consent, not spend consent: nothing here is a purchase, and it never touches a balance either way.Once the loop has actually finished — stopped finding new things, flagged a deeper pattern, or hit its cap after three or more rounds — you can share what it found, as plain numbers. The ask, in plain words: "Share anonymous counts of this loop with nittim — just numbers, never your actual code, file paths or titles? nittim thanks people who report with credits." This is permission to share data, not permission to spend money: nothing here is a purchase, and it never touches your account balance either way.Once the loop stops — converged, flagged systemic, or capped after three or more passes — you can share its counts with nittim: integers only, never code, paths or titles. nittim thanks reporters with credits. This is data consent, not spend consent — it never touches your balance.

What goes: pass numbers, a findings-by-category tally, a fixed count, and whether each pass was clean — nothing else. There is no field for a title, a file path or a snippet; the schema has no room for one.What gets sent: how many rounds it took, a count of problems found by category, how many got fixed, and whether each round came back clean — nothing else. There is no place to put a title, a file path, or a snippet of your code; the data format simply has no room for one.What goes: pass numbers, a findings-by-category tally, a fixed count, and whether each pass was clean — nothing else. No field exists for a title, file path or snippet.

Map your severities: anything that lets a caller read or change what isn't theirs, leak secrets or PHI, or bypass a gate is `high`; `critical` only if it is exploitable today without credentials; the rest `low` — or `medium` when it needs a fix before shipping.

The reward is for a real loop that acted — at least two passes, something fixed, and a real stop: converged, flagged systemic, or capped after three or more passes. 5 credits under 20 repos reported, 3 credits under 100 repos reported, 1 credit under 500 repos reported, then nothing once the corpus reaches 500 — nittim's own report_loop answer always states today's exact number. Capped too: three rewarded repos per account, lifetime, and at most one newly-rewarded repo per account per UTC day. Once the reward reaches zero the report still records; you're simply told there's no reward at this stage.

Reported this repo from this account before? Sending it again updates that record with the new numbers instead of being rejected. The reward is a one-time check, decided when this repo was first reported — even a repo whose first report earned nothing isn't re-checked on a later resubmission — but the numbers on Reported this project from this account before? Sending it again just updates that record with the new numbers instead of being rejected. The reward is a one-time check, decided when this project was first reported — even a project whose first report earned nothing isn't re-checked on a later resubmission — but the numbers on Reported this repo before? Resending it updates the record with new numbers, not a rejection. The reward is a one-time check, decided at first report — even a repo that earned nothing isn't re-checked later — but the numbers on /loop stay current.

Connected over MCP, that's the report_loop tool. Without MCP, the identical shape posts to https://nittim.com/api/v1/loop/report with a bearer key from /keys — it never charges, but it does need one. Either way it shows up, aggregated and counts-only, at If your assistant is connected over MCP (the connector it uses to reach tools), that's the report_loop tool. Without MCP, the same information posts to https://nittim.com/api/v1/loop/report with a bearer key (a password for programs) from /keys — it never charges you, but it does need a key to work. Either way, it shows up combined with everyone else's and counts-only at Over MCP, that's the report_loop tool. Without MCP, post the same shape to https://nittim.com/api/v1/loop/report with a bearer key from /keys — free, but required. Either way it shows up, aggregated and counts-only, at /loop.

2. Run nittim's own scanners on this code

Everything in the checklist runs inside your own assistant, on your own subscription, with nothing leaving your machine. This step is different: it sends your source to nittim's servers to run the same two deterministic scanners — hardcoded secrets and dependency CVEs — against it.Everything in the checklist runs inside your own AI assistant, on your own plan, without sending anything out. This step is different: it sends your code to nittim's servers to run the same two rule-based checks — passwords or keys left in your code, and known security bugs in the ready-made packages your project uses.The checklist runs entirely inside your own assistant, on your own subscription. This step is different — it sends your source to nittim's servers to run the same two deterministic scanners: hardcoded secrets and dependency CVEs.

Consent: your snapshot is private by default and never shown in any public listing, but it does leave your machine. Skip this entirely if you'd rather the review stay local; nothing in the checklist requires it. If you want it, mint a key at /keys, then post your files to POST /api/v1/source/scan — see the API reference. The response is hard evidence only — never a score, never a verdict.Your consent: your copy of the code is private by default and never shown in any public listing, but it does get sent off your computer. Skip this step entirely if you'd rather everything stay on your own machine; nothing in the checklist requires it. If you want to run it, create a key at /keys, then send your files to POST /api/v1/source/scan — see the API reference. What comes back is hard evidence only — never a score, never a final verdict.Consent: your snapshot stays private, never shown publicly, but it does leave your machine. Skip this — nothing in the checklist requires it. To run it, mint a key at /keys, then POST your files to /api/v1/source/scan — see the API reference. The response is hard evidence only, never a score or verdict.

3. Have nittim audit it

A self-review is not an audit, and it can't be made one by grading harder. The one thing that turns "the model that wrote it, checking itself" into an independent result is handing the code to a judge that isn't it. That's worth doing after the loop has gone quiet, on the now-fixed code — not before, because the audit is worth more on code you've already cleaned up.Checking your own work is not the same as an independent check, and grading harder doesn't fix that. The one thing that turns "the AI that wrote it, checking itself" into a real, independent result is handing the code to a different judge that isn't it. That's worth doing once the loop has gone quiet, on the now-fixed code — not before, because the paid check is worth more on code you've already cleaned up yourself for free.A self-review isn't an audit, and grading harder won't make it one. The only way to get an independent result is handing the code to a judge that isn't the model that wrote it. Do this after the loop goes quiet, on the now-fixed code — it's worth more that way.

It uploads your source, and it costs — Audit, 5.14 credits, pass-priced by repo size after that, quoted before anything runs, with a click from you before anything is charged.It uploads your code, and it costs money — Audit, 5.14 credits, priced by how big your project is after that, with the exact price shown before anything runs, and a click from you before anything is charged.It uploads your source, and it costs — Audit, 5.14 credits, then priced by repo size, quoted first, with your click before any charge.

Want nittim's own audit instead — an independent verdict, on credits, with a click from you before any charge? Want nittim to do an independent AI check instead — a verdict from a check that isn't your own assistant, paid in credits, with a click from you before anything is charged? Want nittim's own audit instead — an independent verdict, paid in credits, with your click before any charge? Connect your assistant to nittim

Claude Code

Save it as a project skill so Claude Code picks it up on its own whenever the review is relevant:Save it as a project skill — a saved instruction file — so Claude Code reaches for it on its own whenever a review makes sense:Save it as a project skill — Claude Code picks it up on its own when a review makes sense:

tmpdir="$(mktemp -d)"
if curl -fsSL https://nittim.com/selfcheck.md -o "$tmpdir/selfcheck.md" &&
   printf '%s  %s\n' b84c1da6e63b002cdc75016649066e111e6cd7119ce715ef6be68ef5311ba8b6 "$tmpdir/selfcheck.md" | shasum -a 256 -c - >/dev/null; then
  mkdir -p .claude/skills/nittim-selfcheck
  { printf -- '---\nname: nittim-selfcheck\ndescription: Reviews this codebase against nittim'"'"'s public 13-category production-readiness framework (security, privacy, reliability, and more). Use when asked to self-review, audit, or check the code before shipping.\n---\n\n'; cat "$tmpdir/selfcheck.md"; } > .claude/skills/nittim-selfcheck/SKILL.md
else
  echo "nittim: download failed, or the file does not match the published sha256 — nothing installed"
fi
rm -rf "$tmpdir"

Or install it as an explicit slash command instead:Or install it as a slash command instead — a command you type yourself, starting with a “/”:Or install it as a slash command instead:

tmpdir="$(mktemp -d)"
if curl -fsSL https://nittim.com/selfcheck.md -o "$tmpdir/selfcheck.md" &&
   printf '%s  %s\n' b84c1da6e63b002cdc75016649066e111e6cd7119ce715ef6be68ef5311ba8b6 "$tmpdir/selfcheck.md" | shasum -a 256 -c - >/dev/null; then
  mkdir -p .claude/commands
  cp "$tmpdir/selfcheck.md" .claude/commands/selfcheck.md
else
  echo "nittim: download failed, or the file does not match the published sha256 — nothing installed"
fi
rm -rf "$tmpdir"

Run it with /selfcheck any time, or just ask Claude Code to "run the nittim loop" — either install path works from the next session on.Run it by typing /selfcheck any time, or just ask Claude Code to "run the nittim loop" — either way you set it up, it works starting with your very next session.Run /selfcheck any time, or ask Claude Code to "run the nittim loop" — either way works from your next session on.

Cursor

Save it as a project rule:Save it as a project rule — a saved instruction Cursor keeps for this project:Save it as a project rule:

tmpdir="$(mktemp -d)"
if curl -fsSL https://nittim.com/selfcheck.md -o "$tmpdir/selfcheck.md" &&
   printf '%s  %s\n' b84c1da6e63b002cdc75016649066e111e6cd7119ce715ef6be68ef5311ba8b6 "$tmpdir/selfcheck.md" | shasum -a 256 -c - >/dev/null; then
  mkdir -p .cursor/rules
  { printf -- '---\ndescription: nittim self-check — review this codebase against a public 13-category production-readiness framework\nalwaysApply: false\n---\n\n'; cat "$tmpdir/selfcheck.md"; } > .cursor/rules/nittim-selfcheck.mdc
else
  echo "nittim: download failed, or the file does not match the published sha256 — nothing installed"
fi
rm -rf "$tmpdir"

Reference it in chat with @nittim-selfcheck.mdc review this repo. Leave alwaysApply off — an always-on rule rides along on every chat, the token tax rule 8 in the rubric warns about.Bring it into chat with @nittim-selfcheck.mdc review this repo. Leave alwaysApply off — a rule left always-on rides along on every single chat message, which costs you extra every time, the same warning rule 8 in the checklist gives.Reference it in chat with @nittim-selfcheck.mdc review this repo. Leave alwaysApply off — an always-on rule costs tokens every chat (rubric rule 8).

GitHub Copilot

Save it as a prompt file, so Copilot loads it only when you run it (this won't touch an existing copilot-instructions.md):Save it as a prompt file — an instruction Copilot only loads when you actually run it (this won't touch an existing copilot-instructions.md file you may already have):Save it as a prompt file — Copilot loads it only when you run it (won't touch an existing copilot-instructions.md):

tmpdir="$(mktemp -d)"
if curl -fsSL https://nittim.com/selfcheck.md -o "$tmpdir/selfcheck.md" &&
   printf '%s  %s\n' b84c1da6e63b002cdc75016649066e111e6cd7119ce715ef6be68ef5311ba8b6 "$tmpdir/selfcheck.md" | shasum -a 256 -c - >/dev/null; then
  mkdir -p .github/prompts
  { printf -- '---\ndescription: nittim self-check — review this codebase against a public 13-category production-readiness framework\n---\n\n'; cat "$tmpdir/selfcheck.md"; } > .github/prompts/nittim-selfcheck.prompt.md
else
  echo "nittim: download failed, or the file does not match the published sha256 — nothing installed"
fi
rm -rf "$tmpdir"

Then, in Copilot Chat, type /nittim-selfcheck. Don't save it as an applyTo: "**" instruction file — that rides along on every request, the token tax rule 8 in the rubric warns about.Then, in Copilot Chat, type /nittim-selfcheck. Don't save it as an applyTo: "**" instruction file — that rides along on every request and costs you extra every time, which rule 8 in the checklist warns you not to do.Then type /nittim-selfcheck in Copilot Chat. Don't save it as an applyTo: "**" instruction file — running it costs tokens on every request, which the rubric warns against (rule 8).

Windsurf / Devin Desktop, Cline, or anything reading AGENTS.md

Most other coding agents read one of these conventions. Each install saves the rubric to its own file and leaves a one-line pointer in the file your agent already reads — never the whole rubric in standing context (rule 8 in the rubric):Most other AI coding assistants read one of these setups. Each one saves the checklist to its own file and leaves a one-line pointer in the file your assistant already reads — never the whole checklist sitting there costing you extra on every request (rule 8 in the checklist):Most other coding agents read one of these conventions. Each install saves the rubric to its own file and leaves a pointer in the file your agent reads — never the whole rubric in standing context (rule 8):

AGENTS.md (Codex CLI and a growing list of others)

tmpdir="$(mktemp -d)"
if curl -fsSL https://nittim.com/selfcheck.md -o "$tmpdir/selfcheck.md" &&
   printf '%s  %s\n' b84c1da6e63b002cdc75016649066e111e6cd7119ce715ef6be68ef5311ba8b6 "$tmpdir/selfcheck.md" | shasum -a 256 -c - >/dev/null; then
  mkdir -p .agents
  cp "$tmpdir/selfcheck.md" .agents/selfcheck.md
  printf '\n- See .agents/selfcheck.md for nittim'"'"'s self-check rubric — read it before a pre-ship review, not on every turn.\n' >> AGENTS.md
else
  echo "nittim: download failed, or the file does not match the published sha256 — nothing installed"
fi
rm -rf "$tmpdir"

Windsurf (rebranded Devin Desktop, June 2026)

tmpdir="$(mktemp -d)"
if curl -fsSL https://nittim.com/selfcheck.md -o "$tmpdir/selfcheck.md" &&
   printf '%s  %s\n' b84c1da6e63b002cdc75016649066e111e6cd7119ce715ef6be68ef5311ba8b6 "$tmpdir/selfcheck.md" | shasum -a 256 -c - >/dev/null; then
  mkdir -p .windsurf/rules
  { printf -- '---\ntrigger: manual\ndescription: nittim self-check — review this codebase against a public 13-category production-readiness framework\n---\n\n'; cat "$tmpdir/selfcheck.md"; } > .windsurf/rules/nittim-selfcheck.md
  # Older Windsurf builds (and its 2026 rebrand, Devin Desktop) read only the
  # legacy .windsurfrules file, which is always-on — give it the pointer, not the rubric:
  printf '\n- See .windsurf/rules/nittim-selfcheck.md for nittim'"'"'s self-check rubric — read it before a pre-ship review, not on every turn.\n' >> .windsurfrules
else
  echo "nittim: download failed, or the file does not match the published sha256 — nothing installed"
fi
rm -rf "$tmpdir"

Cline

tmpdir="$(mktemp -d)"
if curl -fsSL https://nittim.com/selfcheck.md -o "$tmpdir/selfcheck.md" &&
   printf '%s  %s\n' b84c1da6e63b002cdc75016649066e111e6cd7119ce715ef6be68ef5311ba8b6 "$tmpdir/selfcheck.md" | shasum -a 256 -c - >/dev/null; then
  mkdir -p .agents
  cp "$tmpdir/selfcheck.md" .agents/selfcheck.md
  printf '\n- See .agents/selfcheck.md for nittim'"'"'s self-check rubric — read it before a pre-ship review, not on every turn.\n' >> .clinerules
else
  echo "nittim: download failed, or the file does not match the published sha256 — nothing installed"
fi
rm -rf "$tmpdir"

If .clinerules is a folder in your repo, put that pointer line in any file inside it instead.

Any other assistant (Grok, ChatGPT, and beyond)

If it doesn't read project files, it can still read the rubric. Use Copy the checklist at the top of this page — that puts the whole checklist on your clipboard under a short covering note — and paste it into the chat. Same file, same categories, same rules, and nothing for your assistant to fetch.If it can't read files from your project, it can still read the checklist. Use Copy the checklist at the top of this page — that puts the whole checklist on your clipboard with a short note above it — and paste it into the chat. Same file, same categories, same rules, and nothing for your assistant to go fetch on its own.If it can't read project files, it can still read the rubric. Use Copy the checklist at the top of this page to put the whole checklist on your clipboard, then paste it into the chat. Same file, categories and rules — nothing for your assistant to fetch.

Already connected over MCP?

If your assistant is already wired up to nittim's MCP server (see for AI agents), it can fetch this rubric directly as the nittim-selfcheck prompt — no install step, no separate file to keep in sync.If your assistant is already connected to nittim over MCP (the connector your AI assistant uses to reach tools — see for AI agents), it can fetch this checklist directly as the nittim-selfcheck prompt — nothing to install, no separate file to keep up to date.If your assistant is already wired up to nittim's MCP server (see for AI agents), it can fetch this rubric directly as the nittim-selfcheck prompt — no install, nothing to keep in sync.

Hand it to your assistant

That's the whole rubric. The simplest way to run it: copy the checklist and paste it to the assistant that wrote the code, in your own words — no terminal, nothing fetched, and it works with anything that can read your repo.That's the whole checklist. The simplest way to run it: copy the checklist and paste it to the assistant that wrote the code, in your own words — no terminal, nothing to fetch, and it works with anything that can read your project.That's the whole rubric. Copy the checklist and paste it to the assistant that wrote the code — no terminal, nothing to fetch, works with anything that can read your repo.

Or hand it the address instead

I’ve chosen a public code-review checklist for us to use on this repo — nittim’s Loop rubric, published at https://nittim.com/selfcheck.md (nittim.com/trust says what nittim does with code). It’s plain prose: questions to ask about code, with no commands in it and nothing to install. Please read it first and tell me what it asks for. If it looks reasonable to you, review this repo against it, category by category, here in this session. If any part of it looks wrong to you, say so and we’ll drop that part — it’s a checklist, not a contract. If you’d rather not open a URL at all, say so and I’ll read it myself and paste the text in from https://nittim.com/selfcheck. Keep it in this conversation — don’t save it into my project or into your standing instructions.

Want an independent second opinion instead? Audit — Want an independent second opinion instead — a check that isn't your own assistant? Audit — Want an independent second opinion? Audit — 5.14 credits run it at nittim.com →