3 favors open right now
This launch is actively rallying. Help out and earn points.

About VibeCheck
vibecheck is a security scanner for GitHub repositories built by developers who use AI coding assistants. It runs four real static analysis tools — Gitleaks, Semgrep, njsscan, and custom checks — against your codebase, then uses Claude AI to explain the findings in plain language and suggest fixes.
Frequently asked questions about VibeCheck
What does VibeCheck do?+
vibecheck is a security scanner for GitHub repositories
Who is VibeCheck for?+
It is designed for developers who use AI coding assistants.
How is vibecheck different from asking an AI to review my code?+
Asking an AI chatbot to review code is non-deterministic and context-limited — it guesses based on what it can see in one prompt window. vibecheck runs deterministic static analysis tools against your full codebase. Claude only appears at the end to translate and prioritize confirmed findings, never to detect vulnerabilities from scratch.
What security scanners does vibecheck run?+
vibecheck runs four scanners in sequence: Gitleaks for exposed secrets and API keys; Semgrep for OWASP Top 10 code patterns including SQL injection, XSS, and path traversal; njsscan for Node.js-specific patterns like missing security headers and eval usage; and 48 custom checks written specifically for AI-generated app patterns — covering secrets exposure, access control, injection attacks, supply chain (malicious postinstall scripts, obfuscated dependencies, binary executables, GitHub Actions permission escalation), AI agent prompt injection (detecting "ignore previous instructions" and cover
Community reviews
No reviews for VibeCheck yet — be the first to leave one.
Support this launch
Members earn points for sharing, reviewing, and giving feedback on VibeCheck. Not a member yet?
Join Favors.dev