{"repo":"benavlabs/vibe-check","free":true,"listed":false,"github":"https://github.com/benavlabs/vibe-check","clone":"git clone https://github.com/benavlabs/vibe-check.git","description":"Security checklist for vibe coded apps. AI rules file + automated audit + manual verification.","language":null,"stars":97,"topics":["agents-md","ai-generated-code","appsec","checklist","claude-code","copilot","cursor","firebase","owasp","pentesting"],"license":"MIT","category":"security-tools","readme_excerpt":"Security checklist for vibe coded apps. AI optimizes for making your code work, not for making it safe. Carnegie Mellon tested this: 61% of AI-generated code is functionally correct, only 10.5% is secure. This repo exists to close that gap. How it works Three layers, no overlap: 1. AGENTS.md — Security rules your AI tool reads while it writes code. Copy into your project root. Prevents vulnerabilities from being created. 2. AI-CHECKLIST.md — A prompt that tells your AI to audit your entire project. It investigates your codebase, writes reports, creates fix plans, implements them, and verifies. 3. manual-checklist.md — Tests you run yourself for the things AI can't catch. Setup Step 1: Copy the rules file into your project Cursor, Copilot, Codex, Windsurf, or Gemini CLI: Claude Code: Not sure? Copy both: Commit it. Your AI tool reads it automatically from now on. Step 2: Run the AI security audit Give AI-CHECKLIST.md to your AI coding assistant: It will investigate your codebase for each of the 17 vulnerability categories, create reports, write fix plans, implement fixes, and verify. Results go in a security/ folder in your project. Step 3: Run the manual checks Open manual-checklist.md and go through each test. These verify things like: can you access another user's data, is your .env exposed, can login be brute-forced. If you only do 5, do the first 5. They cover what took down every company on the list. What this covers 17 most common vulnerabilities found in vibe coded app","default_branch":null,"files":null,"tree":[],"storefront":"/r/benavlabs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/benavlabs/vibe-check/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}