Security Review
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
Security audit for web apps, especially AI-built ("vibe coded") ones.
$ npx skills add benavlabs/vibe-check --skill vibe-check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install benavlabs/vibe-check vibe-check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/benavlabs/vibe-check.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vibe-check .claude/skills/vibe-check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vibe-check" agent skill from https://github.com/benavlabs/vibe-check/tree/main/skills/vibe-check into .claude/skills/vibe-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/benavlabs/vibe-check/tree/main/skills/vibe-checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add benavlabs/vibe-check --skill vibe-check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install benavlabs/vibe-check vibe-check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benavlabs/vibe-check.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/vibe-check .agents/skills/vibe-check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vibe-check" agent skill from https://github.com/benavlabs/vibe-check/tree/main/skills/vibe-check into .agents/skills/vibe-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add benavlabs/vibe-check --skill vibe-check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install benavlabs/vibe-check vibe-check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benavlabs/vibe-check.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/vibe-check .cursor/skills/vibe-check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vibe-check" agent skill from https://github.com/benavlabs/vibe-check/tree/main/skills/vibe-check into .cursor/skills/vibe-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/benavlabs/vibe-check.git --path skills/vibe-check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add benavlabs/vibe-check --skill vibe-check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install benavlabs/vibe-check vibe-check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benavlabs/vibe-check.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/vibe-check .gemini/skills/vibe-check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vibe-check" agent skill from https://github.com/benavlabs/vibe-check/tree/main/skills/vibe-check into .gemini/skills/vibe-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install benavlabs/vibe-check vibe-checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add benavlabs/vibe-check --skill vibe-check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/benavlabs/vibe-check.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/vibe-check .github/skills/vibe-check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vibe-check" agent skill from https://github.com/benavlabs/vibe-check/tree/main/skills/vibe-check into .github/skills/vibe-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add benavlabs/vibe-check --skill vibe-check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install benavlabs/vibe-check vibe-check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benavlabs/vibe-check.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/vibe-check .opencode/skills/vibe-check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vibe-check" agent skill from https://github.com/benavlabs/vibe-check/tree/main/skills/vibe-check into .opencode/skills/vibe-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vibe-check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vibe-checkSecurity audit for web apps, especially AI-built ("vibe coded") ones.
Vibe Check is an agent skill from benavlabs/vibe-check. Security audit for web apps, especially AI-built ("vibe coded") ones. Scans the running app for exposed .env/.git files, public source maps, weak CSP/HSTS/security headers, wildcard CORS, insecure cookies, and public debug/API-docs endpoints, then audits the codebase across 17 vulnerability categories (RLS, auth middleware, IDOR, secrets, SSRF, CSRF, SQLi, XSS, Stripe webhooks, uploads, password hashing, dependencies). Use when the user asks for a security audit or review, asks to check headers/CSP/CORS, or is…
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/AI-CHECKLIST.md` and `scripts/check.py`).
It sits in Security, covering Web application vulnerabilities and Security review. It works with Git, Stripe, Firebase and Supabase. The repository describes itself as: Security checklist for vibe coded apps. AI rules file + automated audit + manual verification. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3afad99. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3gitleaksnpmpnpmyarnsemgrepFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, pnpm and yarn, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vibe Check loads about 1.1k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 136 tokens; SKILL.md has 555 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ones. Scans the running app for exposed .env/.git files, public source maps, weak CSP/HSTS/security headers, wildcard CIf a sensitive file (`.env`, `.git/config`, a key or a dump) is reported as exposed, tell the user **immediately**, befoAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from benavlabs/vibe-check at commit 3afad99, republished under its MIT licence (© benavlabs). 555 words, ~1,129 tokens.
.claude/skills/vibe-check/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Two parts:
scripts/check.py (in this skill's directory) sends read-only requests to the running app and reports PASS/FAIL/WARN per check. It covers categories 1, 5, 7, 8, 9, and 15 from the outside, including things the code can't show you, like headers and CORS added by the host or CDN.references/AI-CHECKLIST.md covers all 17 categories by reading the codebase, writing reports and fix plans, fixing, and verifying.Ask the user for the production or staging URL, plus the API's URL if it's on a different origin (e.g. https://api.example.com/health). Only scan apps the user owns or is authorized to test. If they say it isn't deployed, offer to start the dev server and scan http://localhost:<port>, but tell them local results are incomplete (no HSTS, dev servers serve source maps, host/CDN headers are missing).
python3 <skill-dir>/scripts/check.py https://app.example.com --api https://api.example.com/health --json--only headers,cors limits the categories (secrets,frontend,csrf,headers,cors,errors). --insecure skips TLS verification for self-signed staging certs.--json when you want to show the user the readable report directly.Treat the scan as evidence, not as the audit. Every FAIL has evidence, url, and fix fields. Confirm each one against the code before changing anything, and find where the problem really comes from: app middleware, framework config, or hosting config (vercel.json, netlify.toml, _headers, nginx.conf, Caddyfile, firebase.json, wrangler.toml).
If a sensitive file (.env, .git/config, a key or a dump) is reported as exposed, tell the user immediately, before anything else, that those credentials must be rotated. Don't print the secret values.
Don't reimplement these; run them and include their results:
gitleaks detect --source . --verbose: secrets in git historynpm audit / pnpm audit / yarn npm audit, or pip-audit: vulnerable dependenciessemgrep --config auto (optional): code patternsIf a tool isn't installed, say so in the report and give the install command. Don't install anything without asking.
Follow references/AI-CHECKLIST.md category by category. For categories 1, 5, 7, 8, 9, and 15, start from the scan results; the rest need reading the code. Write reports to security/reports/, plans to security/plans/, and the summary to security/AUDIT_SUMMARY.md, as the checklist describes.
After fixing and deploying, run check.py again and put the before and after counts in AUDIT_SUMMARY.md. If a fix only exists locally, say it's unverified until it's deployed.
frame-ancestors fails most checks, and that's correct. Roll out a new CSP as Content-Security-Policy-Report-Only first so it doesn't break the app. 'unsafe-inline' in style-src is tolerated.preload is reported as optional. Don't add it unless the user confirms every subdomain is HTTPS-only.* CORS on a public JS file, version headers, GraphQL introspection on a public API).© benavlabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts, references) in skills/vibe-check of benavlabs/vibe-check.
Open the folder on GitHubat commit 3afad99
Vibe Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vibe Check this skillbenavlabs/vibe-check | 118 | — | ~1.1k | Automated safety check: Notes | MIT | |
| Security Reviewjewbetcha/opentrace | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Security Reviewkklimuk/docx-cli | 216 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Security Reviewaffaan-m/ECC | 276k | 3 repos | ~2.5k | Automated safety check: Notes | MIT | |
| Security Reviewaffaan-m/ECC | 276k | 2 repos | ~2.5k | Automated safety check: Notes | MIT | |
| Security Reviewaffaan-m/ECC | 276k | 2 repos | ~2.7k | Automated safety check: Notes | MIT |
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
kklimuk/docx-cli
Review code for security vulnerabilities. An agent skill from kklimuk/docx-cli.
affaan-m/ECC
在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。
affaan-m/ECC
認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。
affaan-m/ECC
인증 추가, 사용자 입력 처리, 시크릿 관리, API 엔드포인트 생성, 결제/민감한 기능 구현 시 이 스킬을 사용하세요.
affaan-m/ECC
Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.
Categories
Security audit for web apps, especially AI-built ("vibe coded") ones. Vibe Check is an agent skill from benavlabs/vibe-check. Security audit for web apps, especially AI-built ("vibe coded") ones.
Vibe Check fits situations like: the user asks for a security audit; asks to check headers/CSP/CORS; is about to deploy.
Run `npx skills add benavlabs/vibe-check --skill vibe-check -a claude-code`. Or copy the skill folder (skills/vibe-check in benavlabs/vibe-check) into .claude/skills/vibe-check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add benavlabs/vibe-check --skill vibe-check -a codex`. Or copy the skill folder (skills/vibe-check in benavlabs/vibe-check) into .agents/skills/vibe-check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add benavlabs/vibe-check --skill vibe-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vibe-check, .gemini/skills/vibe-check, .github/skills/vibe-check and .opencode/skills/vibe-check in your project.
Going by SKILL.md and its folder, Vibe Check needs Python for the scripts in its folder and the command-line tools its instructions call (python3, gitleaks, npm, pnpm, yarn and semgrep). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Vibe Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Vibe Check: Security Review (jewbetcha/opentrace, 116 stars), Security Review (kklimuk/docx-cli, 216 stars), Security Review (affaan-m/ECC, 276k stars) and Security Review (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
benavlabs (a GitHub organization) maintains it in benavlabs/vibe-check, which has 118 GitHub stars. The repository was last updated on September 18, 2026.
Source: benavlabs/vibe-check on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.