Security layer for AI-assisted development. One command, permanent protection.
Project description
๐ฐ VibeFort
Security layer for AI-assisted development. One command, permanent protection.
VibeFort protects vibecoders (Cursor, Bolt, Replit, Claude Code users) from supply chain attacks, leaked secrets, and insecure AI-generated code. Run vibefort install once โ it silently protects every package install and git commit forever.
Quick Start
pipx install vibefort
vibefort install
That's it. You never type vibefort again.
Why pipx? VibeFort is a system-wide CLI tool, not a project dependency.
pipxinstalls it globally in an isolated environment โ the standard way to install Python CLI tools. Install pipx if you don't have it:brew install pipx(macOS) orapt install pipx(Ubuntu).
What Happens After Install
# Normal pip usage โ VibeFort intercepts silently
$ pip install flask
โ flask 3.1.0 โ clean (0.2s)
$ pip install reqeusts
โ BLOCKED reqeusts
Possible typosquat โ similar to 'requests'
Did you mean: requests
$ pip install flask-ai-helper-utils
โ BLOCKED flask-ai-helper-utils
Package does not exist on PyPI
This may be a hallucinated package name from an AI tool (slopsquatting)
# Normal git usage โ VibeFort scans staged files
$ git commit -m "add config"
โ VibeFort blocked this commit โ 1 secret(s) found
config.py:14
Detected a Generic API Key
# Docker builds are scanned for insecure patterns
$ docker build .
๐ฐ VibeFort: 3 issue(s) in Dockerfile
CRITICAL Piping remote script directly to shell
HIGH Base image 'python' has no tag (defaults to :latest)
HIGH No USER directive in final stage โ container runs as root
# Dangerous chmod/sudo commands are blocked
$ chmod 777 app.py
๐ฐ VibeFort: World-writable mode 777 allows any user to modify files
BLOCKED: Fix the issue above before proceeding
$ sudo pip install malware
๐ฐ VibeFort: Running 'pip' with sudo can lead to privilege escalation
Supported Package Managers
VibeFort intercepts 12 package managers plus docker, git, chmod, and sudo:
Python
| Manager | Commands intercepted |
|---|---|
pip / pip3 |
pip install flask |
uv |
uv pip install flask, uv add flask |
pipx |
pipx install black |
poetry |
poetry add flask |
pdm |
pdm add flask |
Node.js
| Manager | Commands intercepted |
|---|---|
npm |
npm install, npm add, npm i |
npx |
npx create-react-app (scans before execute) |
yarn |
yarn add express |
pnpm |
pnpm add express |
bun |
bun add express |
bunx |
bunx cowsay (scans before execute) |
npxandbunxare especially dangerous โ they download AND execute code in one step. VibeFort scans the package before allowing execution.
Features
Dockerfile Scanning (automatic, every docker build)
VibeFort intercepts docker build and scans the Dockerfile for security issues:
- Unpinned base images โ
FROM python:latestorFROM python(supply chain risk) - Running as root โ no
USERdirective in the final stage - Remote code execution โ
curl | bash,$(curl ...), inline Python fetch-and-exec - Secrets in ENV/ARG โ API keys, passwords, tokens baked into the image
- ADD from URL โ unverified remote downloads
- Privileged RUN โ
--security=insecurebypass - Heredoc detection โ catches
RUN <<EOF ... curl | bash ... EOF
Critical findings block the build. Dockerfiles in your project are also scanned by vibefort scan.
Git Clone Scanner (automatic, every git clone)
VibeFort scans repositories immediately after cloning:
- Typosquatted orgs โ
git clone github.com/microsft/vscodewarns before cloning - Malicious git hooks โ scans
.git/hooks/for curl|bash, netcat, base64, etc. - Dangerous git config โ detects custom
hooksPath,fsmonitor, and malicious filter drivers - Supports HTTPS, SSH,
git://, and SSH shorthand URL formats
Permission Escalation Guard (automatic)
VibeFort intercepts chmod and sudo to prevent dangerous operations:
- chmod 777/666 โ blocks world-writable permissions (octal and symbolic modes)
- chmod +s โ blocks setuid/setgid bit (privilege escalation)
- sudo pip/npm โ warns against running package managers as root
- sudo rm -rf / โ blocks destructive commands on system paths
- sudo env/su wrappers โ detects attempts to bypass detection via
sudo env piporsudo su -c "pip install"
.env Watchdog (automatic, on directory change)
Monitors .env files every time you change directories:
- Not in .gitignore โ warns if
.env,.env.local,.env.productionetc. would be committed - World-readable โ warns if
.envhas loose permissions - Secrets in .env.example โ detects when example files contain real secret values
Paste Injection Scanner (automatic, ZSH)
Scans clipboard content when you paste into the terminal:
- Hidden Unicode โ zero-width characters, RTL overrides, homoglyphs (Cyrillic/Greek lookalikes)
- ANSI attacks โ cursor manipulation, hidden text, terminal hyperlink spoofing
- OSC/DCS escapes โ terminal control sequences that can execute commands
- Obfuscated payloads โ base64 in comments, hex escape sequences
Malicious pastes are blocked before reaching the terminal.
Config File Guard (automatic, every 5 minutes)
Monitors sensitive dotfiles for unauthorized changes:
- Watches:
~/.ssh/config,~/.ssh/authorized_keys,~/.gitconfig,~/.npmrc,~/.pypirc,~/.aws/credentials,~/.aws/config,~/.docker/config.json,~/.kube/config - Detects: new files, modifications, deletions, and symlink replacements
- Alerts on corrupted snapshots (potential tampering)
Package Scanning (automatic, every install)
Every package install goes through two tiers:
| Tier | What it checks | Speed | When |
|---|---|---|---|
| Tier 1 | Known-safe cache (10k PyPI + 10k npm), typosquatting, slopsquatting, registry existence, CVE check via osv.dev | < 500ms | Every install |
| Tier 2 | Downloads to temp, inspects setup.py/package.json hooks, .pth files, obfuscated code | 3-5s | Unknown packages only |
Secret Scanning (automatic, every commit)
Git pre-commit hook powered by betterleaks (234 detection rules):
- AWS, OpenAI, Anthropic, GitHub, Stripe, Google API keys
- SSH/PGP private keys, JWT tokens
- Database connection strings
- And 220+ more patterns
Code Scanning (vibefort scan)
Scan your project for insecure patterns AI coding tools commonly generate:
$ vibefort scan .
CRITICAL (2)
app.py:12 โ SQL injection โ f-string in database query
utils.py:8 โ Insecure deserialization โ pickle.load can execute arbitrary code
HIGH (3)
run.py:5 โ Command injection risk โ subprocess with shell=True
settings.py:1 โ Debug mode enabled โ should be False in production
app.js:23 โ XSS risk โ innerHTML assignment
5 issue(s) found (2 critical)
Detects: SQL injection, XSS, insecure deserialization (pickle, yaml.load), command injection (shell=True, os.system), debug mode, hardcoded passwords, CORS wildcards, .env not in .gitignore.
Dependency Auditing (vibefort deps)
Audit all project dependencies at once:
$ vibefort deps .
โ reqeusts==2.28.0 (requirements.txt)
Possible typosquat: similar to 'requests'
โ flask==2.0.0 (requirements.txt)
GHSA-xxxx: Known vulnerability (fix: upgrade to 2.3.2)
2 issue(s) found in project dependencies.
Reads requirements.txt, pyproject.toml, package.json, Pipfile, package-lock.json, and poetry.lock. Checks every dependency against typosquatting, CVE databases, and lock file integrity.
System Audit (vibefort audit)
Check if your machine is already compromised:
$ vibefort audit
โ Malicious .pth file โ contains 'import' (executes code every time Python starts)
/usr/lib/python3/site-packages/evil.pth
1 potential issue(s) found.
Checks: malicious .pth files in Python site-packages, known backdoor artifacts, suspicious processes, cron jobs (Linux), LaunchAgents (macOS).
Per-Project Allowlist (.vibefort.toml)
Whitelist packages, files, or rules to prevent false positives:
# .vibefort.toml in your project root
[allow-packages]
"my-internal-sdk" = "private registry"
[allow-files]
"tests/fixtures/fake_keys.py" = "test dummy keys"
[allow-rules]
"generic-api-key" = "false positives in test files"
Auto-Fix Suggestions
When vibefort scan finds issues, it offers to fix them:
.envnot in.gitignoreโ offers to add itDEBUG = Trueโ suggests using environment variables- Hardcoded passwords โ suggests moving to
.env yaml.load()โ suggestsyaml.safe_load()subprocess(shell=True)โ suggests list form
All Commands
| Command | Description |
|---|---|
vibefort install |
One-time setup โ hooks + secret scanner |
vibefort uninstall |
Clean removal of all hooks |
vibefort status |
Dashboard with version, stats, update check |
vibefort scan [path] |
Scan project for secrets + insecure code |
vibefort deps [path] |
Audit all dependencies for vulnerabilities |
vibefort audit |
Check machine for signs of compromise |
vibefort update |
Self-update to latest version |
vibefort config |
View or edit settings |
vibefort completions zsh |
Generate shell completions |
How Install Works
vibefort install does three things that persist forever:
-
Shell hook โ Adds function wrappers to
~/.zshrcor~/.bashrcthat intercept 16 commands (12 package managers +docker,git,chmod,sudo). Also installs.envwatchdog, config file guard, and paste scanner. Loads every time a terminal opens. -
Git hook โ Sets a global pre-commit hook via
git config --global core.hooksPath. Applies to every repo. -
Config guard โ Takes an initial snapshot of sensitive dotfiles (
~/.ssh/*,~/.gitconfig,~/.aws/*, etc.) for change detection.
A ๐ฐ icon appears in your terminal prompt and window title when VibeFort is active, showing scan stats.
vibefort uninstall cleanly removes both.
Security
VibeFort is a security tool โ we take our own security seriously:
- 12 security audits completed (shell injection, path traversal, symlink attacks, TOCTOU races, re-entrancy, regex bypass, system-level interactions)
- All subprocess calls use list form (no
shell=True) - Manager arguments validated against whitelist
- Downloaded binaries verified with SHA256 checksums (fail-closed)
- Atomic file writes for config and checksum files (temp + rename)
- Re-entrancy guard prevents infinite recursion in command wrappers
~/.vibefort/directory set to0700, config to0600- Secret values from scans are never stored or logged
- Scanning uses
--ignore-scripts(npm) and prefers wheels (pip) to prevent code execution during analysis - File scanning has 10MB size limit and skips symlinks
- Shell wrappers degrade gracefully if VibeFort is unavailable
- Compatible with
set -ustrict shell mode - See SECURITY.md for vulnerability reporting
Privacy
VibeFort is local-first. No accounts, no telemetry, no data collection.
Network calls made:
- PyPI/npm registries โ to check if packages exist and for metadata (same as pip/npm themselves)
- osv.dev โ to check for known CVEs (package name + version only)
- GitHub โ to download the betterleaks binary (one-time, on install)
- PyPI โ to check for VibeFort updates (only when you run
vibefort status)
No source code, secrets, or project data ever leaves your machine.
License
MIT โ see LICENSE.
Secret scanning powered by betterleaks (MIT). See THIRD_PARTY_NOTICES.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file vibefort-0.5.0.tar.gz.
File metadata
- Download URL: vibefort-0.5.0.tar.gz
- Upload date:
- Size: 188.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
756c19e25cd09fa64aff398387d7bfa5179e2f7ef770ae01c08345897a7397ad
|
|
| MD5 |
1222d373cd843c3400b1c8fe329231b5
|
|
| BLAKE2b-256 |
428193d9fe3bfc54ff6b1f2f405d778beedc3f59ec3de83f30d6f807db361973
|
Provenance
The following attestation bundles were made for vibefort-0.5.0.tar.gz:
Publisher:
publish.yml on Homecooked-Games-Git/vibefort
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vibefort-0.5.0.tar.gz -
Subject digest:
756c19e25cd09fa64aff398387d7bfa5179e2f7ef770ae01c08345897a7397ad - Sigstore transparency entry: 1199444337
- Sigstore integration time:
-
Permalink:
Homecooked-Games-Git/vibefort@74f3aec154b664304d08bc3a792563b87c32d4f8 -
Branch / Tag:
refs/tags/v0.5.0 - Owner: https://github.com/Homecooked-Games-Git
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@74f3aec154b664304d08bc3a792563b87c32d4f8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file vibefort-0.5.0-py3-none-any.whl.
File metadata
- Download URL: vibefort-0.5.0-py3-none-any.whl
- Upload date:
- Size: 161.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2174d5171544c2c190ecb61cb07154dca4361d76f9a96a56c230750db823bbb0
|
|
| MD5 |
bb0c85e401003ddeee6f7c93936ee84f
|
|
| BLAKE2b-256 |
e356ef5535d1a5e9e908228e42d7cf23cced7e79ba576b1294d6f232da6a3601
|
Provenance
The following attestation bundles were made for vibefort-0.5.0-py3-none-any.whl:
Publisher:
publish.yml on Homecooked-Games-Git/vibefort
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vibefort-0.5.0-py3-none-any.whl -
Subject digest:
2174d5171544c2c190ecb61cb07154dca4361d76f9a96a56c230750db823bbb0 - Sigstore transparency entry: 1199444348
- Sigstore integration time:
-
Permalink:
Homecooked-Games-Git/vibefort@74f3aec154b664304d08bc3a792563b87c32d4f8 -
Branch / Tag:
refs/tags/v0.5.0 - Owner: https://github.com/Homecooked-Games-Git
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@74f3aec154b664304d08bc3a792563b87c32d4f8 -
Trigger Event:
push
-
Statement type: