One command. A pattern engine plus a Gemini review pass — unauthenticated endpoints, leaked secrets, injection and prompt injection. The report lands in the folder you scanned.
more security vulnerabilities in AI-generated code vs human-written code
CodeRabbit, 2025of AI-generated applications contain exploitable OWASP vulnerabilities
Veracode, 2025vibe-coded apps found with virtually no security or authentication
Dor Zvi research, 2026more privilege escalation paths in AI code than human-written code
Apiiro, 2025Traditional tools were built before AI coding existed. VibeGuard is built for the patterns AI actually produces.
Regex finds the obvious. Gemini reads your highest-risk files end to end and reports the exploit path — where untrusted input enters, what it reaches, and why the guard that should stop it isn't there.
// Entry: GET /api/orders/:id
req.params.id ← untrusted
→ router.js:23
→ orderService.js:87
→ db.query(`SELECT * WHERE id = ${id}`)
⚠ SQL injection — no ownership check
A database of known-bad patterns AI models produce repeatedly across unrelated projects. Mass assignment, algorithm confusion, unsafe deserialization — caught before they ship.
AWS, Google, OpenAI, Anthropic, GitHub, Stripe and database credentials in source — plus server secrets accidentally shipped to the browser through NEXT_PUBLIC_, VITE_ and REACT_APP_ prefixes.
The defect AI backends ship most often: a route that writes to the database with no session check anywhere in the file. VibeGuard flags every mutating handler that has no auth guard.
For apps that integrate LLMs, VibeGuard maps every path where user-controlled data flows into a prompt without sanitization — the #1 vulnerability in OWASP's LLM Top 10.
Not a wall of CVE IDs. Every finding names the file and line, links the CWE, explains how it's exploited, and gives a copy-paste fix. Written into the folder you scanned as Markdown for your team and JSON for CI.
No config files. No accounts. No setup. Point it at your project directory and it figures out the rest — language, framework, and which files carry real risk.
A deterministic pattern engine sweeps every file in under a second. Then the highest-risk files — routes, auth, config, LLM integrations — go to Gemini in parallel for the logic and authorization flaws patterns can't see.
A prioritized report written straight into the folder you scanned — CWE references, the vulnerable line, and a copy-paste fix for each finding. Markdown for your team, JSON for CI, and a 0–100 security score.
VibeGuard is an npm package. Run it instantly with npx, install it globally, or drop it into any CI/CD pipeline.
The fastest way to audit any project. No global install needed — npx pulls the latest version automatically.
Install once and run vibeguard from any project directory on your machine.
Fail the build on high-severity findings with --fail-on. Add --no-ai to keep runs deterministic and free. Works in GitHub Actions, GitLab CI, and more.
Prompt injection, model output reaching eval/shell/DOM, unsafe LLM integration patterns
Mutating routes with no auth guard, stubbed or hardcoded checks, public database rules
SQL concatenation, shell commands, eval, unsafe deserialization, NoSQL operator injection
Provider API keys, private keys, database URIs, secrets leaked into client bundles
JWTs decoded without verification, alg:none, insecure session cookie flags
MD5/SHA-1 password hashing, Math.random() for tokens, weak work factors
Wildcard CORS, disabled TLS verification, debug mode on, wildcard host allow-lists
dangerouslySetInnerHTML, innerHTML from variables, document.write
Containers running as root, --privileged, chmod 777, committed .env files
Business logic flaws, missing ownership checks and over-broad responses, found by the Gemini pass
No account. No config. No excuses.