Automated security audit and remediation skill for vibe-coded apps...
⚠️ Disclaimer: This skill identifies and fixes the most common vulnerability patterns in vibe-coded apps. It is not a substitute for a professional penetration test for high-stakes applications handling sensitive data, financial transactions, or regulated information. For those cases, engage a qualified security firm after running this skill.
You built something great — now let's make sure it's safe to ship. This skill acts like a senior security engineer reviewing your codebase. It scans your project, figures out which security checks are relevant (skipping anything that doesn't apply to your app), then identifies vulnerabilities and fixes them directly in your code. When it's done, you get a clean report showing what was found, what was fixed, and anything that needs your attention.
No configuration needed. Just activate it and let it run.
When this skill is activated, follow these four phases in order. Read the full module specifications in
references/modules.md before beginning Phase 1.
Before touching any code, build a map of what exists in the project. This determines which security modules to run and which to skip.
Scan for the following signals:
Stack detection — Check for package.json, requirements.txt, Pipfile, Gemfile, composer.json,
go.mod, Cargo.toml. Identify the primary language and framework (Next.js, Express, FastAPI, Django,
Rails, Laravel, etc.).
Authentication signals — Look for files/patterns: auth, login, signup, register, session,
passport, nextauth, supabase/auth, firebase/auth, bcrypt, argon2, password_hash,
devise, sanctum. Also grep for password in route/controller files.
JWT signals — Search for jwt, jsonwebtoken, jose, PyJWT, jwt-decode, Bearer,
sign(, verify( in server files, localStorage.setItem near token storage.
Password reset signals — Search for reset, forgot, resetToken, reset_token,
sendPasswordReset, password_reset in routes, controllers, or API files.
Admin route signals — Search for /admin, isAdmin, role, permission, middleware/admin,
admin.js, admin.py, admin_required.
File upload signals — Search for multer, formidable, busboy, UploadFile, FileField,
has_attached_file, store(, S3, cloudinary, multipart, enctype="multipart/form-data".
Webhook signals — Search for /webhook, stripe.webhooks, svix, HMAC, x-hub-signature,
webhook_secret in route files.
Database query signals — Search for raw SQL patterns: query(, execute(, raw(, ${} inside
SQL strings, f"SELECT, sprintf with SQL, .where( with string interpolation.
Frontend rendering signals — Search for innerHTML, dangerouslySetInnerHTML, eval(,
document.write(, v-html (Vue), [innerHTML] (Angular).
CORS signals — Search for cors(, Access-Control-Allow-Origin, origin: '*', CORS_ORIGIN,
add_middleware(CORSMiddleware.
Error handling signals — Search for console.error, res.status(500).json, print(traceback,
render json: { error:, return JsonResponse({ 'error':.
Dependency manifest — Check for package.json, package-lock.json, yarn.lock,
requirements.txt, Pipfile.lock, Gemfile.lock, composer.lock.
Deployment config signals — Check for .env, .env.example, docker-compose.yml, Dockerfile,
vercel.json, railway.toml, render.yaml, fly.toml, Heroku Procfile.
Secrets exposure signals — Scan ALL files (especially .js, .ts, .py, .rb, .php,
.env, .json, .yml) for patterns: sk_live_, sk_test_, AKIA, AIza, ghp_, hardcoded
connection strings with passwords, mongodb+srv://user:password.
After scanning, output a Reconnaissance Report:
## 🔍 Reconnaissance Complete
**Stack detected:** [e.g., Next.js 14 / TypeScript / PostgreSQL / Prisma]
**Security modules that will run:**
- [x] SEC-01: Secrets & API Key Exposure (hardcoded keys found in 2 files)
- [x] SEC-02: Secure Authentication (auth system detected)
- [ ] SEC-03: JWT Security — SKIPPED (no JWT usage detected)
...
**Modules skipped:** SEC-03, SEC-04, SEC-09, SEC-11
**Reason for skips:** Listed inline above
Execute each applicable module from references/modules.md in order (SEC-01 through SEC-13). For each module:
references/modules.md[SEC-XX] Modifying <filename>: replacing <old pattern> with <new pattern> because <reason>Severity levels:
Run the appropriate audit command based on detected package manager:
| Package Manager | Command |
|---|---|
| npm / yarn / pnpm | npm audit --json |
| pip | pip-audit --format json (install with pip install pip-audit if missing) |
| Bundler (Ruby) | bundle audit check --update (install with gem install bundler-audit if missing) |
| Composer (PHP) | composer audit |
| Go modules | govulncheck ./... (install with go install golang.org/x/vuln/cmd/govulncheck@latest if missing) |
Parse the output and:
After all checks are complete, generate the following report. This report should be saved as
SECURITY_AUDIT_REPORT.md in the project root AND printed to the conversation.
See references/report_template.md for the exact report format to use.
references/modules.md — Full specifications for all 15 security check modules (SEC-01 through SEC-15)references/report_template.md — Exact template for the final security reportRead both reference files before beginning Phase 1.
Recommended repository structure:
vibe-security-check/
├── SKILL.md ← This file
├── references/
│ ├── modules.md ← All 15 security check modules
│ └── report_template.md ← Security report template
├── evals/
│ └── evals.json ← Test cases
├── README.md ← Human-friendly intro (see below)
├── LICENSE ← MIT License
└── .github/
└── CONTRIBUTING.md ← Contribution guidelines
README.md should include:
LICENSE: Use MIT License. Template at https://opensource.org/licenses/MIT
To publish: Create a new GitHub repo, push this directory, add topics: security, claude-skill,
vibe-coding, owasp, ai-coding-tools.
SKILL.md and the references/ directory as a zipskillmp publish ./vibe-security-check (install with npm i -g skillmp)skillmp validate first to catch any schema issues