Yes, I use skipfish for some tests, though I customized parts of it (it has an amazing web crawler). I also use proprietary scan technology, and plan to add a few more open source tools into the mix (such as port/service and virus scanning) in the not so distant future to create one combined risk/vulnerability report.
interesting file is typically a text file, unsecured htaccess file, or sometimes 500 error messages. If you tell me your site, I will check for you.
target market is small business, medium size business, or individual site owners - mostly those who don't maintain a full time IT security staff but want some visibility into their site risks. Eventually I may add PCI checks, but that is a huge compliance/paper cost which is tough for a one man shop to keep up with.