Built for the vibe coding era

Your AI built it fast.
We make sure it's not a disaster.

One command. A pattern engine plus a Gemini review pass — unauthenticated endpoints, leaked secrets, injection and prompt injection. The report lands in the folder you scanned.

$ npx @vidhaankhare/vibeguard scan .
View on GitHub →
30+ Pattern rules
2 Analysis engines
0 Config required
vibeguard — scan
$ npx @vidhaankhare/vibeguard scan .
 ██╗ ██╗██╗██████╗ ███████╗ ██████╗ ██╗ ██╗ █████╗ ██████╗ ██████╗
 ╚██╗ ██╔╝██║██████╔╝█████╗ ██║ ███╗██║ ██║███████║██████╔╝██║ ██║
  v2.0.0 · Gemini-powered security auditing for AI-generated code
 
✓ Read 218 files (24,910 lines)
✓ Pattern analysis found 19 issue(s)
✓ Gemini review found 12 additional issue(s)
 
Security score  32/100 ⚠ DANGEROUS
 
CRITICAL  Missing authentication on a mutating API route
          src/app/api/admin/reset/route.ts:4
CRITICAL  Secret exposed to the client bundle
          src/lib/stripe.ts:8
HIGH   Unsanitized user input interpolated into an LLM prompt
          src/app/actions/chat.ts:22
 
→ SECURITY-REPORT.md
→ vibeguard-report.json
  Completed in 6.2s
█

The vibe coding security crisis is real

2.74×

more security vulnerabilities in AI-generated code vs human-written code

CodeRabbit, 2025
45%

of AI-generated applications contain exploitable OWASP vulnerabilities

Veracode, 2025
5,000

vibe-coded apps found with virtually no security or authentication

Dor Zvi research, 2026
322%

more privilege escalation paths in AI code than human-written code

Apiiro, 2025
What makes it different

Not just another linter.
An extraordinary audit.

Traditional tools were built before AI coding existed. VibeGuard is built for the patterns AI actually produces.

🔍

Reads the code, not just patterns

Regex finds the obvious. Gemini reads your highest-risk files end to end and reports the exploit path — where untrusted input enters, what it reaches, and why the guard that should stop it isn't there.

Exploit path reported
// Entry: GET /api/orders/:id
req.params.id  ← untrusted
  → router.js:23
  → orderService.js:87
  → db.query(`SELECT * WHERE id = ${id}`)
⚠ SQL injection — no ownership check
🤖

AI pattern signatures

A database of known-bad patterns AI models produce repeatedly across unrelated projects. Mass assignment, algorithm confusion, unsafe deserialization — caught before they ship.

🔑

Secrets, including leaked ones

AWS, Google, OpenAI, Anthropic, GitHub, Stripe and database credentials in source — plus server secrets accidentally shipped to the browser through NEXT_PUBLIC_, VITE_ and REACT_APP_ prefixes.

🔓

Unauthenticated endpoints

The defect AI backends ship most often: a route that writes to the database with no session check anywhere in the file. VibeGuard flags every mutating handler that has no auth guard.

💉

Prompt injection mapping

For apps that integrate LLMs, VibeGuard maps every path where user-controlled data flows into a prompt without sanitization — the #1 vulnerability in OWASP's LLM Top 10.

📊

Reports built for developers

Not a wall of CVE IDs. Every finding names the file and line, links the CWE, explains how it's exploited, and gives a copy-paste fix. Written into the folder you scanned as Markdown for your team and JSON for CI.

CRITICAL
BOLA — Unauthenticated access to any user's data
src/api/users.js:47 · CWE-639
HIGH
JWT algorithm confusion — alg:none accepted
src/middleware/auth.js:12 · CWE-347
HIGH
Hardcoded AWS access key ID
src/config/aws.ts:8 · CWE-798
How it works

Three steps to a full audit

01

Install & run

No config files. No accounts. No setup. Point it at your project directory and it figures out the rest — language, framework, and which files carry real risk.

$ npx @vidhaankhare/vibeguard scan .
02

Two engines run

A deterministic pattern engine sweeps every file in under a second. Then the highest-risk files — routes, auth, config, LLM integrations — go to Gemini in parallel for the logic and authorization flaws patterns can't see.

03

Get your report

A prioritized report written straight into the folder you scanned — CWE references, the vulnerable line, and a copy-paste fix for each finding. Markdown for your team, JSON for CI, and a 0–100 security score.

Install

Run anywhere, zero setup

VibeGuard is an npm package. Run it instantly with npx, install it globally, or drop it into any CI/CD pipeline.

npx

Run without installing

The fastest way to audit any project. No global install needed — npx pulls the latest version automatically.

$ npx @vidhaankhare/vibeguard scan .
global

Install globally

Install once and run vibeguard from any project directory on your machine.

$ npm install -g @vidhaankhare/vibeguard
$ vibeguard scan .
CI/CD

GitHub Actions & pipelines

Fail the build on high-severity findings with --fail-on. Add --no-ai to keep runs deterministic and free. Works in GitHub Actions, GitLab CI, and more.

$ npx @vidhaankhare/vibeguard scan . --fail-on high
Coverage

10 layers of security analysis

01

LLM & AI Security

Prompt injection, model output reaching eval/shell/DOM, unsafe LLM integration patterns

02

Authorization & Access Control

Mutating routes with no auth guard, stubbed or hardcoded checks, public database rules

03

Injection Vulnerabilities

SQL concatenation, shell commands, eval, unsafe deserialization, NoSQL operator injection

04

Secrets & Credentials

Provider API keys, private keys, database URIs, secrets leaked into client bundles

05

Authentication & Sessions

JWTs decoded without verification, alg:none, insecure session cookie flags

06

Cryptography

MD5/SHA-1 password hashing, Math.random() for tokens, weak work factors

07

Security Misconfiguration

Wildcard CORS, disabled TLS verification, debug mode on, wildcard host allow-lists

08

Cross-Site Scripting

dangerouslySetInnerHTML, innerHTML from variables, document.write

09

Infrastructure & Deployment

Containers running as root, --privileged, chmod 777, committed .env files

10

Logic & Data Exposure

Business logic flaws, missing ownership checks and over-broad responses, found by the Gemini pass

Run your first audit in 30 seconds

No account. No config. No excuses.

$ npx @vidhaankhare/vibeguard scan .