Agent skill

Vibe Check

by benavlabs in benavlabs/vibe-check

Security audit for web apps, especially AI-built ("vibe coded") ones.

MITAuto-check: notesSecurity

Install Vibe Check

skills CLI
$ npx skills add benavlabs/vibe-check --skill vibe-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install benavlabs/vibe-check vibe-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/benavlabs/vibe-check.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vibe-check .claude/skills/vibe-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vibe-check
GitHub stars
118
Token cost
~1.1k tokens
SKILL.md length
555 words
Files
3 (incl. scripts, references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Security audit for web apps, especially AI-built ("vibe coded") ones.

  • Works in 5 steps: Get a target → Run the live scan → Run existing tools if they're installed → …
  • The user asks for a security audit
  • SKILL.md covers Workflow and Interpreting results
  • Runs Python scripts from its folder; calls python3, gitleaks and npm

What it does

Vibe Check is an agent skill from benavlabs/vibe-check. Security audit for web apps, especially AI-built ("vibe coded") ones. Scans the running app for exposed .env/.git files, public source maps, weak CSP/HSTS/security headers, wildcard CORS, insecure cookies, and public debug/API-docs endpoints, then audits the codebase across 17 vulnerability categories (RLS, auth middleware, IDOR, secrets, SSRF, CSRF, SQLi, XSS, Stripe webhooks, uploads, password hashing, dependencies). Use when the user asks for a security audit or review, asks to check headers/CSP/CORS, or is…

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/AI-CHECKLIST.md` and `scripts/check.py`).

It sits in Security, covering Web application vulnerabilities and Security review. It works with Git, Stripe, Firebase and Supabase. The repository describes itself as: Security checklist for vibe coded apps. AI rules file + automated audit + manual verification. The licence is MIT.

When your agent uses it

  • The user asks for a security audit
  • Asks to check headers/CSP/CORS
  • Is about to deploy

Example prompts

  • “vibe coded”
  • “/vibe-check”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Get a target
  2. Run the live scan
  3. Run existing tools if they're installed
  4. Audit the code
  5. Re-scan after fixing

What it can do on your machine

Read from SKILL.md and the folder at commit 3afad99. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • gitleaks
    • npm
    • pnpm
    • yarn
    • semgrep

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, pnpm and yarn, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vibe Check loads about 1.1k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 136 tokens; SKILL.md has 555 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:3
    ones. Scans the running app for exposed .env/.git files, public source maps, weak CSP/HSTS/security headers, wildcard C
  • NoteMentions a .env fileSKILL.md:32
    If a sensitive file (`.env`, `.git/config`, a key or a dump) is reported as exposed, tell the user **immediately**, befo

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from benavlabs/vibe-check at commit 3afad99, republished under its MIT licence (© benavlabs). 555 words, ~1,129 tokens.

Download SKILL.mdSave it as .claude/skills/vibe-check/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
vibe-check
description
Security audit for web apps, especially AI-built ("vibe coded") ones. Scans the running app for exposed .env/.git files, public source maps, weak CSP/HSTS/security headers, wildcard CORS, insecure cookies, and public debug/API-docs endpoints, then audits the codebase across 17 vulnerability categories (RLS, auth middleware, IDOR, secrets, SSRF, CSRF, SQLi, XSS, Stripe webhooks, uploads, password hashing, dependencies). Use when the user asks for a security audit or review, asks to check headers/CSP/CORS, or is about to deploy.

vibe-check

Two parts:

  1. Live scan: scripts/check.py (in this skill's directory) sends read-only requests to the running app and reports PASS/FAIL/WARN per check. It covers categories 1, 5, 7, 8, 9, and 15 from the outside, including things the code can't show you, like headers and CORS added by the host or CDN.
  2. Code audit: references/AI-CHECKLIST.md covers all 17 categories by reading the codebase, writing reports and fix plans, fixing, and verifying.

Workflow

1. Get a target

Ask the user for the production or staging URL, plus the API's URL if it's on a different origin (e.g. https://api.example.com/health). Only scan apps the user owns or is authorized to test. If they say it isn't deployed, offer to start the dev server and scan http://localhost:<port>, but tell them local results are incomplete (no HSTS, dev servers serve source maps, host/CDN headers are missing).

2. Run the live scan
bash
python3 <skill-dir>/scripts/check.py https://app.example.com --api https://api.example.com/health --json
  • Python 3.8+ standard library only; nothing to install.
  • Exit code 0 = no failures, 1 = at least one FAIL, 2 = target unreachable (report the error; don't guess results).
  • --only headers,cors limits the categories (secrets,frontend,csrf,headers,cors,errors). --insecure skips TLS verification for self-signed staging certs.
  • Leave out --json when you want to show the user the readable report directly.

Treat the scan as evidence, not as the audit. Every FAIL has evidence, url, and fix fields. Confirm each one against the code before changing anything, and find where the problem really comes from: app middleware, framework config, or hosting config (vercel.json, netlify.toml, _headers, nginx.conf, Caddyfile, firebase.json, wrangler.toml).

If a sensitive file (.env, .git/config, a key or a dump) is reported as exposed, tell the user immediately, before anything else, that those credentials must be rotated. Don't print the secret values.

3. Run existing tools if they're installed

Don't reimplement these; run them and include their results:

  • gitleaks detect --source . --verbose: secrets in git history
  • npm audit / pnpm audit / yarn npm audit, or pip-audit: vulnerable dependencies
  • semgrep --config auto (optional): code patterns

If a tool isn't installed, say so in the report and give the install command. Don't install anything without asking.

Show full SKILL.md (210 more words)Show less
4. Audit the code

Follow references/AI-CHECKLIST.md category by category. For categories 1, 5, 7, 8, 9, and 15, start from the scan results; the rest need reading the code. Write reports to security/reports/, plans to security/plans/, and the summary to security/AUDIT_SUMMARY.md, as the checklist describes.

5. Re-scan after fixing

After fixing and deploying, run check.py again and put the before and after counts in AUDIT_SUMMARY.md. If a fix only exists locally, say it's unverified until it's deployed.

Interpreting results

  • CSP: the scanner parses each directive. A header that's present with only frame-ancestors fails most checks, and that's correct. Roll out a new CSP as Content-Security-Policy-Report-Only first so it doesn't break the app. 'unsafe-inline' in style-src is tolerated.
  • HSTS preload is reported as optional. Don't add it unless the user confirms every subdomain is HTTPS-only.
  • Cookies: only cookies set on the landing page are visible. Session cookies set after login need the manual check (DevTools → Application → Cookies).
  • WARN means worth fixing, but not a vulnerability on its own (e.g. * CORS on a public JS file, version headers, GraphQL introspection on a public API).
  • Not covered by the scan: RLS, auth middleware, IDOR, SSRF, rate limiting, SQLi, XSS, webhooks, uploads, password hashing, dependencies. Never report these as passing based on the scan.

© benavlabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in skills/vibe-check of benavlabs/vibe-check.

  • SKILL.md
  • references/AI-CHECKLIST.md
  • scripts/check.py

Open the folder on GitHubat commit 3afad99

Compare with similar skills

Vibe Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vibe Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vibe Check this skillbenavlabs/vibe-check118—~1.1kAutomated safety check: NotesMIT
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Security Reviewkklimuk/docx-cli216—~1.7kAutomated safety check: PassMIT
Security Reviewaffaan-m/ECC276k3 repos~2.5kAutomated safety check: NotesMIT
Security Reviewaffaan-m/ECC276k2 repos~2.5kAutomated safety check: NotesMIT
Security Reviewaffaan-m/ECC276k2 repos~2.7kAutomated safety check: NotesMIT

Similar skills

  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Security Review

    kklimuk/docx-cli

    Review code for security vulnerabilities. An agent skill from kklimuk/docx-cli.

    216 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check passed
  • Security Review

    affaan-m/ECC

    在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。

    276k GitHub starsUsed in 3 repos~2.5k tokens
    SecurityAuto-check: notes
  • Security Review

    affaan-m/ECC

    認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。

    276k GitHub starsUsed in 2 repos~2.5k tokens
    SecurityAuto-check: notes
  • Security Review

    affaan-m/ECC

    인증 추가, 사용자 입력 처리, 시크릿 관리, API 엔드포인트 생성, 결제/민감한 기능 구현 시 이 스킬을 사용하세요.

    276k GitHub starsUsed in 2 repos~2.7k tokens
    SecurityAuto-check: notes
  • Security Review

    affaan-m/ECC

    Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

    276k GitHub starsUsed in 1 repo~3.2k tokens
    SecurityAuto-check: notes

Categories

Questions about Vibe Check

What does Vibe Check do?

Security audit for web apps, especially AI-built ("vibe coded") ones. Vibe Check is an agent skill from benavlabs/vibe-check. Security audit for web apps, especially AI-built ("vibe coded") ones.

When should I use Vibe Check?

Vibe Check fits situations like: the user asks for a security audit; asks to check headers/CSP/CORS; is about to deploy.

How do I install Vibe Check in Claude Code?

Run `npx skills add benavlabs/vibe-check --skill vibe-check -a claude-code`. Or copy the skill folder (skills/vibe-check in benavlabs/vibe-check) into .claude/skills/vibe-check in your project. Claude Code loads it when a task matches its description.

How do I install Vibe Check in Codex?

Run `npx skills add benavlabs/vibe-check --skill vibe-check -a codex`. Or copy the skill folder (skills/vibe-check in benavlabs/vibe-check) into .agents/skills/vibe-check in your project. Codex loads it when a task matches its description.

Can I use Vibe Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add benavlabs/vibe-check --skill vibe-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vibe-check, .gemini/skills/vibe-check, .github/skills/vibe-check and .opencode/skills/vibe-check in your project.

What does Vibe Check need to run?

Going by SKILL.md and its folder, Vibe Check needs Python for the scripts in its folder and the command-line tools its instructions call (python3, gitleaks, npm, pnpm, yarn and semgrep). Our summary lists: Python 3.

Does Vibe Check access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Vibe Check safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vibe Check use?

Vibe Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vibe Check use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.6k tokens, read only when the agent opens those files.

What are the alternatives to Vibe Check?

Skills that share tags, products or a category with Vibe Check: Security Review (jewbetcha/opentrace, 116 stars), Security Review (kklimuk/docx-cli, 216 stars), Security Review (affaan-m/ECC, 276k stars) and Security Review (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vibe Check?

benavlabs (a GitHub organization) maintains it in benavlabs/vibe-check, which has 118 GitHub stars. The repository was last updated on September 18, 2026.

Source: benavlabs/vibe-check on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.