Skip to main content

Security scanner for AI-generated code

Project description

🔒 VibeSec

Security scanner for AI-generated code.

VibeSec v0.2.0 License: MIT Python 3.8+ GitHub stars

45% of AI-generated code ships with critical vulnerabilities. Cursor, Claude Code, Bolt, and Lovable generate insecure patterns that existing tools miss. VibeSec catches them before you deploy.

$ vibesec scan ./my-cursor-app

  VibeSec v0.2.0 — AI-Generated Code Security Scanner

  ● CRITICAL    7 findings
  ● HIGH        2 findings

  CRITICAL — Hardcoded Secret
  File: src/lib/supabase.ts  Line: 12
  Found: SUPABASE_SERVICE_KEY hardcoded in source code
  Fix:   Move to environment variables. Never commit secrets to git.

  CRITICAL — Supabase RLS Disabled
  File: supabase/migrations/001_init.sql  Line: 34
  Found: ALTER TABLE users DISABLE ROW LEVEL SECURITY
  Fix:   Enable RLS + add user isolation policies.

  9 findings in ./my-cursor-app

Why VibeSec

Existing tools like Semgrep, Snyk, and CodeQL are great — but they were built for human-written code. AI tools generate specific anti-patterns that these scanners miss:

Pattern Semgrep Snyk VibeSec
Hardcoded secrets
Supabase RLS disabled
Hallucinated npm packages
Missing auth on scaffolded routes Partial
Source map exposure in build config
AI-specific JWT misuse

Install

pip install vibesec

Usage

Scan a directory:

vibesec scan ./my-project

Scan and get AI-powered fix suggestions:

vibesec scan ./my-project --fix

Export results as JSON (for CI/CD):

vibesec scan ./my-project --output json

Filter by severity:

vibesec scan ./my-project --severity critical

Ignore specific checks:

vibesec scan ./my-project --ignore rls,cors

What VibeSec Checks

🔴 CRITICAL

1. Hardcoded Secrets API keys, passwords, tokens, and database URLs hardcoded in source files. LLMs replicate tutorial patterns where secrets are hardcoded.

# VibeSec catches this
api_key = "sk-abc123..."
SUPABASE_SERVICE_KEY = "eyJhbGci..."
stripe_secret = "sk_live_..."

2. Supabase RLS Disabled Row Level Security disabled — any authenticated user can read or modify all data. LLMs skip RLS to make queries work quickly in scaffolding.

-- VibeSec catches this
ALTER TABLE users DISABLE ROW LEVEL SECURITY;

3. SQL Injection Risk SQL built via string concatenation, f-strings, or format interpolation instead of parameterized queries.

🟡 HIGH

4. Missing Route Authentication Admin and sensitive API routes scaffolded without authentication middleware. LLMs build the happy path without thinking about access control.

5. Hallucinated Packages npm packages that don't exist — a typosquatting attack surface. LLMs generate plausible-sounding package names that aren't real.

// VibeSec catches this
"react-auth-handler": "^1.0.0",
"supabase-helpers": "^2.1.0"

6. Source Map Exposure Build config exposes full source code via .map files in production.

7. Unsafe JWT Handlingnone algorithm, verification disabled, or tokens stored in web storage

8. Client-Side Role Trust — Admin checks done using client-controlled values (localStorage/URL params)

9. Insecure Flask Configuration — DEBUG mode, hardcoded SECRET_KEY, or weak fallback key

10. Credentials in Environment File — Real API keys or DB URLs committed in .env

🟠 MEDIUM

11. Unsafe HTML Injection (XSS)dangerouslySetInnerHTML, innerHTML, or eval with dynamic input

12. Missing Webhook Verification — Stripe/GitHub webhooks without signature check

13. Permissive CORS Configuration — Wildcard CORS with credentials enabled


GitHub Actions Integration

Add VibeSec to your CI/CD pipeline:

# .github/workflows/vibesec.yml
name: VibeSec Security Scan

on: [push, pull_request]

jobs:
  security:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - uses: actions/setup-python@v4
        with:
          python-version: '3.11'
      - name: Install VibeSec
        run: pip install vibesec
      - name: Run Security Scan
        run: vibesec scan . --output json --severity high

Development

git clone https://github.com/AyushkhatiDev/vibesec
cd vibesec
python -m venv venv
source venv/bin/activate
pip install -e ".[dev]"
pytest tests/

Contributing

VibeSec is open source and contributions are welcome.

Adding a new rule:

  1. Create vibesec/rules/your_rule.py
  2. Implement check_your_rule(file_path, content) -> list[dict]
  3. Register it in vibesec/rules/__init__.py
  4. Add test cases in tests/corpus/
  5. Open a PR

Each finding must return:

{
    "rule": "Rule Name",
    "severity": "CRITICAL|HIGH|MEDIUM|LOW",
    "file": file_path,
    "line": line_number,
    "message": "What was found",
    "fix_hint": "How to fix it",
    "code_snippet": "offending line"
}

See CONTRIBUTING.md for full guide.


Roadmap

  • Secrets detection
  • Supabase RLS checker
  • Missing auth on routes
  • Hallucinated package detector
  • Source map exposure
  • JWT misuse rules
  • dangerouslySetInnerHTML XSS detection
  • Client-side role trust
  • Webhook verification
  • Permissive CORS
  • Flask SECRET_KEY and debug mode detection
  • Credentials in .env files
  • SQL injection patterns
  • .vibesecignore support
  • AI-powered fix suggestions (Groq)
  • GitHub Action marketplace listing
  • Scan public GitHub repos by URL
  • Web app (paste URL → get report)
  • SARIF output for GitHub Security tab
  • VS Code extension

Built By

Ayush Khati — BCA student building real tools for real problems.

Found a bug? Open an issue. Want a rule added? Start a discussion.


License

MIT — free to use, modify, and distribute.


Built because 45% of vibe-coded apps ship with critical vulnerabilities. Someone had to fix that.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vibesec-0.3.0.tar.gz (30.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vibesec-0.3.0-py3-none-any.whl (30.8 kB view details)

Uploaded Python 3

File details

Details for the file vibesec-0.3.0.tar.gz.

File metadata

  • Download URL: vibesec-0.3.0.tar.gz
  • Upload date:
  • Size: 30.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.21

File hashes

Hashes for vibesec-0.3.0.tar.gz
Algorithm Hash digest
SHA256 e60720014402dfa407846f68e89c49a66a5dbe8880544fff62ed72e0fb65a95d
MD5 c973d4ba45c5d92e85ec6a91129b230e
BLAKE2b-256 1ab3da5ae63f939fb20d6ae67da624ae74051884a2bed24486163530e5e3c056

See more details on using hashes here.

File details

Details for the file vibesec-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: vibesec-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 30.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.21

File hashes

Hashes for vibesec-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 0ee4385f767b6ed028c27f1adfc4a43fae9ce21b252deee731bee36bfa69a9e5
MD5 31f239e43ed13ad36b87efcaa749ccd3
BLAKE2b-256 6ac328a9608cad462cd0a7a8ab18e92b1aeec08e904227dd67453356a1ab5365

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page