Skip to main content

🛡️ VibeGuard

Your AI coding agent writes fast. It also commits AWS keys at 2am.

License: MIT Python 3.10+

VibeGuard is a pre-commit hook and GitHub Action that stops AI-generated code from shipping secrets, hardcoded API keys, and security holes — before they ever reach your repo.

VibeGuard catching a leaked Stripe key


The problem

AI coding agents are incredible — and they have zero survival instinct. They'll happily:

  • Hardcode your Stripe live key "just to get it working"
  • Commit a .env with production credentials
  • Write SQL with string concatenation and call it done

VibeGuard sits between your agent and your repo and says no.

Quickstart

pip install vibeguard-secrets
vibeguard init        # writes .vibeguard.toml

Add to your pre-commit config:

repos:
  - repo: https://github.com/Shifu34/vibeguard
    rev: v0.1.0
    hooks:
      - id: vibeguard
pre-commit install

That's it. The next time your agent stages a secret, the commit is blocked:

VibeGuard found 2 potential secret(s):

  HIGH   src/payments.py:14  stripe-live-key
         Stripe live secret key
         stripe.api_key = "sk_live_4eC39HqLyjW..."

  MEDIUM src/config.py:3  high-entropy-secret
         High-entropy value assigned to 'api_token' (possible hardcoded secret)

Remove the secret, or allowlist the path in .vibeguard.toml

What it catches

Rule Severity Example
AWS access / secret / session keys high/high/medium AKIAIOSFODNN7EXAMPLE
Azure storage keys, GCP service-account keys high AccountKey=..., "type": "service_account"
Stripe live & restricted keys high sk_live_...
Twilio, SendGrid, Mailgun keys high SK..., SG..., key-...
GitHub tokens (PAT, OAuth, app) high ghp_..., gho_...
GitLab PATs, npm / PyPI tokens high glpat-..., npm_..., pypi-...
Heroku, DigitalOcean, Cloudflare tokens high/high/medium dop_v1_...
Slack tokens & webhooks high xoxb-...
Discord bot tokens & webhooks high discord.com/api/webhooks/...
OpenAI, Anthropic, Hugging Face, Google keys high sk-..., sk-ant-..., hf_..., AIza...
Private key blocks high -----BEGIN RSA PRIVATE KEY-----
DB connection strings with credentials high postgres://admin:s3cret@...
High-entropy assignments medium api_token = "a9F3kQ7z..." (no known prefix needed)

32 rules total, plus a generic secret-assignment pattern for the long tail.

Plus an optional LLM review that reads the actual diff and flags what regexes can't: SQL injection, auth bypass, insecure crypto, SSRF, path traversal. Enable it with:

[llm]
enabled = true
model = "gpt-4o-mini"   # any OpenAI-compatible endpoint works
export VIBEGUARD_API_KEY="..."

GitHub Action

Scan every PR diff automatically:

- uses: Shifu34/vibeguard@v0.1.0
  with:
    base: origin/${{ github.base_ref }}
    # llm-review: "true"
    # api-key: ${{ secrets.VIBEGUARD_API_KEY }}

Configuration

vibeguard init writes a .vibeguard.toml — all knobs in one place:

fail_on = "high"   # "high" or "medium"

allowlist = [
  "*.md",
  "docs/**",
  "tests/**",
]

[llm]
enabled = false
model = "gpt-4o-mini"
# base_url = "https://api.openai.com/v1"

Manual scans:

vibeguard scan            # staged changes (what's about to commit)
vibeguard scan --all      # every tracked file
vibeguard scan --base origin/main   # diff against a branch (CI)
vibeguard scan --format json        # machine-readable output
vibeguard scan --format sarif       # SARIF 2.1.0 (e.g. for GitHub code scanning)

Why not gitleaks / trufflehog?

Those are excellent secret scanners — VibeGuard happily stands on their shoulders conceptually. The difference:

  • Built for the agent era: the threat isn't a tired dev, it's a tireless agent committing at machine speed. VibeGuard is optimized for pre-commit speed and agent workflows.
  • LLM diff review: catches logic-level vulnerabilities (injection, auth bypass), not just known secret formats.
  • 60-second setup: one pip install, one pre-commit block, zero config required.
  • Zero dependencies: the core scanner is stdlib-only Python.

Roadmap

  • More secret rules (Twilio auth tokens, Vault tokens, ...)
  • .env and config-file aware scanning
  • VS Code / JetBrains extensions
  • vibeguard --fix: auto-move secrets to env vars

Contributing

PRs welcome — especially new secret rules with tests. See tests/test_secrets.py for the pattern: one rule, one test, one line of regex.

pip install -e ".[dev]" 2>/dev/null || pip install -e .
python -m pytest

License

MIT — go build something safe with it.


⭐ If VibeGuard saves you from one leaked key, give it a star. That's the whole business model.

Metadata

Release files for vibeguard-secrets 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vibeguard-secrets 0.1.1
File Size Uploaded
vibeguard_secrets-0.1.1.tar.gz 20.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vibeguard-secrets 0.1.1
File Interpreter ABI Platform
vibeguard_secrets-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 35.5 kB

Release files / vibeguard_secrets-0.1.1.tar.gz

Download URL vibeguard_secrets-0.1.1.tar.gz
Size 20.3 kB
Tags Source
SHA-256 checksum
How to use checksums
a2d904b6ff6fb13a43b7ee5c4464a75c86f47fb0dd698e5c4c98ac0aaf94deb9
BLAKE2b-256 checksum
How to use checksums
bc00d508f398934c2f40abbcbba423504505697f5fe6f3427016cdc17ec2b247
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.10

Release files / vibeguard_secrets-0.1.1-py3-none-any.whl

Download URL vibeguard_secrets-0.1.1-py3-none-any.whl
Size 15.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
86074bcb9c7e13b29e15ce1a3e57962f7f9dfe0d693ef6be56db5e86fc0ae198
BLAKE2b-256 checksum
How to use checksums
1c4d7ac2abb2f028d5fc3906d9d240bf78c8fcaa8063302ddedff7d70e2a11e6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.10

Release history Release notifications | RSS feed

0.3.0

2 release files

0.1.2

2 release files

This release

0.1.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page