Flagged: dynamic eval(). Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by tanviet12 · Claude Skill · ★ 282
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is vbsec safe to install? View the security audit →
🇻🇳 Đọc bằng Tiếng Việt → README.vi.md vbsec — Source Code Security Scanner A multi-platform agent skill that performs in-depth security scans and detects 20+ of the most common security vulnerabilities in your source code. Runs natively on Claude Code, OpenAI Codex CLI, and Google Antigravity. Introduction AI-generated code now represents a meaningful share of new commits across the industry. While modern coding assistants excel at producing code that works, they routinely ship code with classic security pitfalls: hardcoded secrets, SQL injection, missing access controls, weak password hashing, JWT misuse, and broken CORS configurations. These mistakes rarely surface in functional testing — they surface in incident reports. vbsec brings production-grade security review into the AI coding loop. It runs as a native agent skill on three platforms — type in Claude Code, (or ) in OpenAI Cod
| Stars | 282 |
| Forks | 132 |
| Language | Python |
| Category | Claude Skill |
| License | MIT |
| Quality Score | 70.639355215532/100 |
| Open Issues | 1 |
| Last Updated | 2026-09-28 |
| Created | 2026-05-13 |
| Platforms | claude-code, codex, python |
| Est. Tokens | ~16k |
These tools work well together with vbsec for enhanced workflows:
Looking for a vbsec alternative? If you're comparing vbsec with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Open-source cybersecurity analysis agent for Claude Code. Scans projects for vulnerabilities across all OWASP
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (
AI-powered cybersecurity code review skill for Claude Code. 8 specialist agents, OWASP 2025, CWE Top 25, MITRE
Offline security scanner for AI-agent repos, skills, plugins, and MCP servers.
Open-source Python, TypeScript, and Go SAST with dead code detection. Finds secrets, exploitable flows, and
The definitive resource for Agent Skills - modular capabilities revolutionizing AI agent architecture
Explore other popular claude skill tools:
vbsec is Security scanning skill for Claude Code, Codex and Antigravity. Finds the 21 most common vulnerabilities in AI-written code and shows how to fix each one.. It is categorized as a Claude Skill with 282 GitHub stars.
vbsec is primarily written in Python. It covers topics such as agent-skills, ai-code-review, antigravity.
You can find installation instructions and usage details in the vbsec GitHub repository at github.com/tanviet12/vbsec. The project has 282 stars and 132 forks, indicating an active community.
vbsec is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to vbsec on Agent Skills Hub include cyber-neo, agent-security-scanner-mcp, claude-cybersecurity. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: