Run env, security, SEO and dependency checks on each client site
Agencies juggle many client repos with the same recurring chores. Tillwren gives every developer the same Claude Code skills: catch env vars missing from .env.example before a deploy, run a security pass, audit pages for SEO problems, find unused or undeclared packages and write release notes for the client.
How web teams use Tillwren
- Install Tillwren once per developer (or Team for up to 10 developers).
- Before a client deploy, run env-drift and security-pass in the repo.
- Run seo-audit on the staging URL and fix HIGH issues first.
- Use release-notes and pr-polish to write the client update.
In our test repo, seo-audit found 21 page issues across 2 pages (4 HIGH) and dep-audit flagged lodash and flask as unused and zod as undeclared.
The Team tier adds a house-style skill so every developer's output follows the agency's conventions.
What the skills found in our test repo (tests/fixture.py), 9 Oct 2026
| Skill | Found | Count |
|---|---|---|
| security-pass | hard-coded token, SQL string concat, eval of request body, TLS verify off | 4 |
| env-drift | env vars read in code but missing from .env.example | 4 |
| seo-audit | page issues across 2 pages (4 HIGH) | 21 |
| test-gaps | public functions no test references | 7 |
| dep-audit | unused (lodash, flask) / undeclared (zod) packages | 3 |
Source: products/tillwren/store/listing.json (skill results on the test fixture repo, 9 Oct 2026).
FAQ
Can I use it on client projects?
Yes. The licence covers personal and commercial use on your own and client projects; it does not allow reselling or sharing the files.
Is there a team licence?
Team is $149 once for up to 10 developers in one company, with private-repo setup and the house-style skill.
Tillwren: full guide with prices and alternatives · All use cases · Store