A Claude Code / Codex skill that audits a website for scraping & clone resistance and prescribes real hardening — without the snake-oil.
Honest premise: you can't 100% prevent copying of rendered content (a browser shows it → it can be saved). Disabling right-click is theatre that breaks UX/SEO/accessibility. The real wins are raising the cost, detecting clones, proving ownership (DMCA) — and the one true 100% block: keep protected data behind server-side auth so it never reaches the client at all. This skill optimizes for exactly those.
Give it a URL or point it at your local codebase. It audits 9 areas and returns a 0–100 score + prioritized fixes:
- Asset hotlink protection
- Bot / scraping defenses (WAF, captcha, rate limit)
- AI crawler opt-out (GPTBot, CCBot, Google-Extended, ClaudeBot…)
- Content canary / fingerprint (prove a clone copied you)
- Image watermarking
- Copy friction (flagged as friction, not security)
- Source/code exposure (sourcemaps, comments, secrets)
- Framing/embedding + DMCA readiness
- Exposed data endpoints / API auth — the gated-UI-but-open-API trap, the #1 real scraping vector (this is the one you can block 100%)
Most "copy protection" lies. Here's the honest split:
| Tier | Lever | Guarantee |
|---|---|---|
| 🔒 Hard block (100%) | Auth-gated server endpoints — protected data never sent to the client | ✅ The server simply doesn't answer. Deterministic. |
| 🔒 Hard block (100%) | AI-crawler opt-out (compliant crawlers), hotlink 403, iframe frame-ancestors |
✅ Enforced for anything that obeys the rules / hits your server. |
| 🛡️ Defense-in-depth | Canary tokens, watermarks, DMCA readiness | Can't prevent — but you detect the clone and prove it's yours, then take it down. |
| Right-click / select / copy blocking | Bypassed in 1 second. Hurts UX/SEO/a11y. Flagged, never sold as security. |
The skill scores each area honestly and tells you which tier each fix belongs to.
On request (fix mode) it doesn't just advise — it applies hardening directly to your codebase: generates robots.txt/ai.txt, adds CSP frame-ancestors/X-Frame-Options headers, injects a canary token, scaffolds a DMCA page, turns off production sourcemaps, and produces hotlink rules (Apache/Nginx) for you to deploy.
git clone https://github.com/be-realdeveloper/copyguard
cd copyguard && ./install.shOr copy manually into ~/.claude/skills/copyguard.
In a new Claude Code session:
/copyguard https://yoursite.com
or just: "audit my site for clone/copy resistance: https://yoursite.com"
Run it against your local repo and add fix to apply the hardening automatically:
/copyguard . fix
MIT. Use it, fork it, ship it. PRs welcome — especially new crawler signatures and detection recipes.
B개발자 는 코드를 몰라도 AI로 직접 만드는 시대 — 비개발자 전성시대를 만드는 빌더입니다. 비개발자도 바로 쓸 수 있는 바이브코딩 스킬을 오픈소스로 공유합니다 (see also patch, untangle, secuaudit).
Built by B개발자 · 비개발자 전성시대 · litt.ly/be_realdeveloper