Task. A mobile car detailer sends a customer a quote as a link. The customer opens it on a phone, accepts and pays a deposit, and the owner sees every status on a dashboard. I asked Bolt to build this from scratch in one prompt. What came back looked finished: a dashboard, a list of quotes and a clean customer page.
Check. Before I call an app done, I look at it the way a stranger would, with only the public link. My script takes the database address and the public key from the page code (every visitor's browser already gets that key) and asks each table for rows without logging in. It only reads, and it counts rows instead of printing them. The whole run took about a minute.
Finding. Bolt had made the quotes table readable by anyone. A stranger could pull 8 of 8 quotes with each customer's name, phone, email and home address, plus the private link that lets the customer accept and pay. The settings table was open as well, and anyone could create an account in the app's database without confirming an email.

Fix. I described the fix to Bolt in one prompt. Anonymous reads of quotes and settings were removed. The customer page now loads a single quote through a database function that checks the link, and accepting, declining or paying goes through functions that check the link, the expiry date and the quote's status. After that I switched off new sign-ups in the Bolt Database settings and made an unknown link show "Quote not found".
Result. The same check, run again the same day: quotes and settings answer 401 without a login, and 0 rows come back. A customer's own link still opens their quote on a 390 px phone and on a desktop screen, and the owner dashboard works as before. I ran the check once more before publishing this page, with the same result.
Scope. The outside check shows what a stranger can reach. It does not read the source code line by line; that is the full review, a separate job.
