vibe-check

Run a 30-point security audit on AI-built apps and produce a scored report with remediation guidance.

Updated Apr 7, 2026
One-click install
npx skills add https://github.com/namenroh/a-vibe-check --skill vibe-check-namenroh
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vibe-check
Source: https://github.com/namenroh/a-vibe-check/tree/main
Command: npx skills add https://github.com/namenroh/a-vibe-check --skill vibe-check-namenroh

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

AI-generated apps often ship with subtle security gaps and misconfigurations that break trust and complicate deployment. This Skill provides a structured, 30-point security audit to identify vulnerabilities, quantify risk with a score, and map findings to compliance frameworks.

Core Features & Use Cases

  • Comprehensive checks across secrets, authentication, authorization, input handling, infrastructure, and data exposure to reveal common security gaps in vibe-coded apps.
  • Generates a scored report with prioritized remediation guidance and mapping to OWASP/SOC2/PCI GDPR where applicable.
  • Useful for pre-shipment security reviews, code audits, and ongoing security hardening for AI-assisted development workflows.

Quick Start

Run the vibe-check skill on your project directory to generate a scorecard and remediation plan.

Frequently Asked Questions about vibe-check

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit on AI-generated code?

A security audit for AI-generated apps runs a 30-point check across your codebase to identify secrets, auth flaws, injections, and misconfigurations, generating a structured scorecard with prioritized remediation steps.

What does a code security scorecard include for compliance mapping?

A code security scorecard includes a quantified risk score, prioritized remediation guidance, and mappings to compliance frameworks like OWASP, SOC2, PCI, and GDPR where applicable to your deployment context.

Can I use this security audit for pre-shipment code reviews?

Yes, you can use this security audit for pre-shipment code reviews to check secrets, authorization, input handling, infrastructure, and data exposure to reveal common security gaps in AI-assisted development workflows.

How does automated security scoring work for vibe-coded apps?

Automated security scoring works by evaluating diverse codebases and deployment contexts against 30 points, quantifying risk to surface misconfigurations and compliance gaps in a structured report for AI-built apps.

What are common security vulnerabilities in AI-built apps?

Common security vulnerabilities in AI-built apps include exposed secrets, authentication weaknesses, injection flaws, infrastructure misconfigurations, and data exposure gaps across diverse codebases and deployment contexts.