Agent skill

The Vibe Check

by mohitagw15856 in mohitagw15856/pm-claude-skills

Harden a vibe-coded app before strangers use it — the audit for prototypes built fast with AI: exposed secrets, missing auth checks, unvalidated input, data with no deletion path, and the five…

MITAuto-check: notes

Install The Vibe Check

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill the-vibe-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills the-vibe-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/the-vibe-check .claude/skills/the-vibe-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
the-vibe-check
GitHub stars
1.4k
Token cost
~1.5k tokens
SKILL.md length
762 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Harden a vibe-coded app before strangers use it — the audit for prototypes built fast with AI: exposed secrets, missing auth checks, unvalidated input, data with no deletion path, and the five…

  • Works in 5 steps: Secrets in the client. API keys in… → Auth theater. The UI hides the admin… → The database trusts everyone.… → …
  • Someone says Claude built my app
  • SKILL.md covers What This Skill Produces, Required Inputs, Framework: the five… and Output Format, plus 4 more sections
  • Calls npm

What it does

The Vibe Check is an agent skill from mohitagw15856/pm-claude-skills. Harden a vibe-coded app before strangers use it — the audit for prototypes built fast with AI: exposed secrets, missing auth checks, unvalidated input, data with no deletion path, and the five embarrassing holes every weekend build has. Use when someone says 'Claude built my app, is it safe to launch', 'harden my prototype', 'vibe check my project', or before putting real users on a hackathon build. Produces a ranked findings list with fixes, a launch-blocker line, and a 'what I'd break first' attacker's tour…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Someone says Claude built my app
  • Is it safe to launch
  • Harden my prototype
  • Vibe check my project

Example prompts

  • “Claude built my app, is it safe to launch”
  • “harden my prototype”
  • “vibe check my project”
  • “/the-vibe-check”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Secrets in the client. API keys in frontend JS, .env committed to the
  2. Auth theater. The UI hides the admin button but the endpoint answers
  3. The database trusts everyone. Default-open row-level security, every
  4. Input goes straight in. Unvalidated input into queries, prompts
  5. Data with no exit. Storing more than needed, no deletion path, AI

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

The Vibe Check loads about 1.5k tokens when it runs. Until then it costs about 141 tokens; SKILL.md has 762 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~141
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:41
    n the client.** API keys in frontend JS, .env committed to the

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 762 words, ~1,525 tokens.

Download SKILL.mdSave it as .claude/skills/the-vibe-check/SKILL.md (or your agent's skills folder).
name
the-vibe-check
description
Harden a vibe-coded app before strangers use it — the audit for prototypes built fast with AI: exposed secrets, missing auth checks, unvalidated input, data with no deletion path, and the five embarrassing holes every weekend build has. Use when someone says 'Claude built my app, is it safe to launch', 'harden my prototype', 'vibe check my project', or before putting real users on a hackathon build. Produces a ranked findings list with fixes, a launch-blocker line, and a 'what I'd break first' attacker's tour. Defensive review of YOUR OWN app.

The Vibe Check Skill

Vibe coding is real and good: an idea becomes a working app in a weekend. Then the app gets users, and the things that didn't matter Friday night matter enormously — the API key sitting in client code, the endpoint that trusts the browser to say who's logged in, the database where every user can read every row. This skill is the bridge from "it works" to "strangers can use it": a structured self-audit ordered by embarrassment-per-fix, honest about what must block launch versus what can wait for week two. It reviews the user's own app — it's a seatbelt, not a lockpick.

What This Skill Produces

  • A ranked findings list: 🔴 launch-blockers / 🟡 week-one / 🟢 eventually, each with the concrete fix (and the code-level change where code was shared)
  • The attacker's tour: "here's what I'd try first on your app" — the 10- minute walkthrough of your own front door, as motivation and test plan
  • A launch checklist for this specific stack, not a generic OWASP dump
  • The data honesty check: what you're storing, whether you need it, and whether you can delete it when a user asks

Required Inputs

Ask for (if not already provided):

  • What the app does and who's about to use it (5 friends? the internet? payments? minors? — the bar moves)
  • The stack: framework, hosting, database, auth approach, AI APIs used
  • Access to look: the repo/key files pasted, or answers to the checklist questions honestly ("is the Supabase anon key doing all your auth? be honest")
  • What the AI assistant built vs what the user wrote/reviewed — unreviewed generated code is where the holes cluster

Framework: the five embarrassing holes (check these first)

  1. Secrets in the client. API keys in frontend JS, .env committed to the repo, keys in the mobile bundle. Fix: server-side proxy for anything with a bill or a scope; rotate anything that ever shipped to a browser — it's burned, rotation is not optional.
  2. Auth theater. The UI hides the admin button but the endpoint answers anyone; user ID taken from the request body; "logged in" checked in React but not on the server. Fix: every endpoint re-checks identity and authorization server-side; the client is a rumor, not a witness.
  3. The database trusts everyone. Default-open row-level security, every user can query every row, the AI wrote select * where it meant where user_id =. Fix: RLS/scoped queries, then test as a second user — the two-account test finds most of it.
  4. Input goes straight in. Unvalidated input into queries, prompts (injection into your LLM calls — your system prompt is not a secret once users can talk to it), file uploads with no limits, HTML rendered unescaped. Fix: validate server-side, parameterize, cap sizes, escape output, treat LLM output shown to other users as untrusted input too.
  5. Data with no exit. Storing more than needed, no deletion path, AI conversation logs kept forever by default, no answer to "delete my account." Fix: store less, add the delete path now (retrofitting it after growth is 10x the work), write the three-line privacy note that matches reality.

Then the supporting cast: rate limits on anything that costs money per call (your AI endpoints especially — one loop = one invoice) · error messages that don't leak stack traces · dependency audit (npm audit is free) · backups tested once · the bus factor file (how to deploy, where the keys live).

Show full SKILL.md (204 more words)Show less

Output Format

## Vibe check: [app] — verdict: [SHIP / SHIP AFTER RED / NOT YET]

## Findings
| # | 🔴🟡🟢 | The hole | Where | The fix (specific) |

## The attacker's 10-minute tour of your app
[First thing I'd try · second · third — each mapped to a finding]

## Launch checklist (your stack)
- [ ] [concrete, checkable items]

## Data honesty
[Storing → needed? → deletable? · the 3-line privacy note]

## What's genuinely fine
[The vibe-coded parts that hold up — credit where due]

Quality Checks

  • Findings cite the user's actual code/answers — zero generic-scanner filler for holes their stack can't even have
  • Every 🔴 has a specific fix, and shipped-to-client secrets say ROTATE, not just "remove"
  • The two-account test and the rate-limit-on-paid-APIs check appear whenever applicable
  • The verdict line is committed — one of the three, with the 🔴 count carrying the reasoning
  • Something is marked genuinely fine — an audit that only condemns teaches less than one that also confirms

Anti-Patterns

  • Do not audit apps the user doesn't own or operate — this skill hardens your own front door; decline recon on others' apps
  • Do not produce exploit code — findings name the hole and the fix; the attacker's tour describes attempts, not payloads
  • Do not perfection-block a launch — the 🔴/🟡/🟢 split exists because "fix everything first" means never shipping, which is its own failure
  • Do not shame the vibe coding — the weekend build was the right call; this is just the Monday that follows

[[security-threat-model]] for the grown-up version; [[injection-spotter]] for the prompt-injection deep-dive; [[local-dev-setup]] and [[monitoring-setup-guide]] for the operational half of "real app."

Example Trigger Phrases

  • "Is it safe to launch?"
  • "Claude built my app: is it secure?"
  • "Harden my prototype before strangers use it."
  • "Vibe check my project."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/the-vibe-check of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

The Vibe Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

The Vibe Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
The Vibe Check this skillmohitagw15856/pm-claude-skills1.4k—~1.5kAutomated safety check: NotesMIT
Vibe Code Cleanupsickn33/agentic-awesome-skills47k1 repos~1.8kAutomated safety check: NotesMIT
Vibe Coding PartnershareAI-lab/Kode-CLI5.2k—~5.6kAutomated safety check: PassApache-2.0
Code Reviewflutter/flutter180k—~1.4kAutomated safety check: PassBSD-3-Clause
Simplify CodeNousResearch/hermes-agent252k—~3.7kAutomated safety check: PassMIT
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0

Similar skills

  • Vibe Code Cleanup

    sickn33/agentic-awesome-skills

    Safe production cleanup and hardening for vibe-coded fullstack apps (Next.js, React, Node.js, etc.).

    47k GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check: notes
  • Vibe Coding Partner

    shareAI-lab/Kode-CLI

    Gives an agent a set of working rules for any development task: understand first, surface decisions, verify results, and load deeper reference files per scenario.

    5.2k GitHub stars~5.6k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Code Review

    flutter/flutter

    Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback.

    180k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Simplify Code

    NousResearch/hermes-agent

    Parallel 4-agent cleanup of recent code changes. An agent skill from NousResearch/hermes-agent.

    252k GitHub stars~3.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Architectural Code Review

    Donchitos/Claude-Code-Game-Studios

    Performs an architectural review of code against coding standards, SOLID, testability and performance, and reports no verdict when the inputs are missing.

    26k GitHub stars~3.5k tokensUpdated 3 days ago
    DevelopmentAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about The Vibe Check

What does The Vibe Check do?

Harden a vibe-coded app before strangers use it — the audit for prototypes built fast with AI: exposed secrets, missing auth checks, unvalidated input, data with no deletion path, and the five…. The Vibe Check is an agent skill from mohitagw15856/pm-claude-skills. Harden a vibe-coded app before strangers use it — the audit for prototypes built fast with AI: exposed secrets, missing auth checks, unvalidated input, data with no deletion path, and the five embarrassing holes every weekend build has.

When should I use The Vibe Check?

The Vibe Check fits situations like: someone says Claude built my app; is it safe to launch; harden my prototype; vibe check my project.

How do I install The Vibe Check in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill the-vibe-check -a claude-code`. Or copy the skill folder (skills/the-vibe-check in mohitagw15856/pm-claude-skills) into .claude/skills/the-vibe-check in your project. Claude Code loads it when a task matches its description.

How do I install The Vibe Check in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill the-vibe-check -a codex`. Or copy the skill folder (skills/the-vibe-check in mohitagw15856/pm-claude-skills) into .agents/skills/the-vibe-check in your project. Codex loads it when a task matches its description.

Can I use The Vibe Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill the-vibe-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/the-vibe-check, .gemini/skills/the-vibe-check, .github/skills/the-vibe-check and .opencode/skills/the-vibe-check in your project.

What does The Vibe Check need to run?

Going by SKILL.md and its folder, The Vibe Check needs the command-line tools its instructions call (npm).

Does The Vibe Check access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is The Vibe Check safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does The Vibe Check use?

The Vibe Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does The Vibe Check use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to The Vibe Check?

Skills that share tags, products or a category with The Vibe Check: Vibe Code Cleanup (sickn33/agentic-awesome-skills, 47k stars), Vibe Coding Partner (shareAI-lab/Kode-CLI, 5.2k stars), Code Review (flutter/flutter, 180k stars) and Simplify Code (NousResearch/hermes-agent, 252k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains The Vibe Check?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.