No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by benavlabs · AI Skill · ★ 110
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is vibe-check safe to install? View the security audit →
Security checklist for vibe coded apps. AI optimizes for making your code work, not for making it safe. Carnegie Mellon tested this: 61% of AI-generated code is functionally correct, only 10.5% is secure. This repo exists to close that gap. How it works Three layers, no overlap: — Security rules your AI tool reads while it writes code. Copy into your project root. Prevents vulnerabilities from being created. — A prompt that tells your AI to audit your entire project. It investigates your codebase, writes reports, creates fix plans, implements them, and verifies. — Tests you run yourself for the things AI can't catch. Setup Step 1: Copy the rules file into your project Cursor, Copilot, Codex, Windsurf, or Gemini CLI: Claude Code: Not sure? Copy both: Commit it. Your AI tool reads it automatically from now on. ###
| Stars | 110 |
| Forks | 11 |
| Language | Python |
| Category | AI Skill |
| License | MIT |
| Quality Score | 71.9883840158261/100 |
| Last Updated | 2026-09-18 |
| Created | 2026-04-02 |
| Platforms | claude-code, python |
| Est. Tokens | ~5k |
These tools work well together with vibe-check for enhanced workflows:
Looking for a vibe-check alternative? If you're comparing vibe-check with other ai skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Claude Code skill for OWASP security best practices (2025-2026). Includes Top 10:2025, ASVS 5.0, Agentic AI se
Become 10x Vibe Coder. Awesome Vibe Coding guide, best practices, and tips for efficient and controlled AI ass
AI-powered cybersecurity code review skill for Claude Code. 8 specialist agents, OWASP 2025, CWE Top 25, MITRE
Pre-configured agent skills for Vibe Coded projects. These skills provide AI coding assistants (Claude Code, C
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (
Security testing toolkit for Claude Code: curated SecLists wordlists, injection payloads, and expert agents fo
Explore other popular ai skill tools:
vibe-check is Security checklist for vibe coded apps. AI rules file + automated audit + manual verification.. It is categorized as a AI Skill with 110 GitHub stars.
vibe-check is primarily written in Python. It covers topics such as agents-md, ai-generated-code, appsec.
You can find installation instructions and usage details in the vibe-check GitHub repository at github.com/benavlabs/vibe-check. The project has 110 stars and 11 forks, indicating an active community.
vibe-check is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to vibe-check on Agent Skills Hub include claude-code-owasp, awesome-vibe-coding-guide, claude-cybersecurity. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: