{"repo":"luisfer/ubon","free":true,"listed":false,"github":"https://github.com/luisfer/ubon","clone":"git clone https://github.com/luisfer/ubon.git","description":"Peace of mind for vibe-coded apps","language":"TypeScript","stars":49,"topics":["nextjs","python","react","security","vibe-coding","vibe-coding-assistant","typescript"],"license":"MIT","category":"security-tools","readme_excerpt":"🪷 Ubon Security scanner for AI-generated apps. Catches the bugs Cursor, Lovable, Windsurf, v0, and Claude routinely ship: hardcoded LLM keys, prompt-injection sinks, leaked Server Actions, hallucinated imports, missing auth on streaming endpoints, and the other \"looks fine to a linter\" issues that traditional tools miss. Quick start Why Ubon? Modern AI coding assistants are great at producing code that runs . They are routinely careless about code that's safe to deploy : - Hardcoded LLM API keys in client bundles - Server Actions with no auth check - Streaming routes with no rate limit - MCP server configs with literal secrets - import.meta.env.PUBLIC reading server-only values - 'use client' files importing from actions/ - Edge runtime routes calling Node-only APIs - Hallucinated imports that pass the type checker because the package never gets installed Ubon's job is to catch those, fast, with high confidence and file:line context — and to expose them to the agent itself via JSON / NDJSON / MCP so the AI can fix what it broke. v3.2.0 — what's new v3.2.0 is an additive release for agentic development workflows: installable guardrails, richer machine-readable output, and a validation harness that proves Ubon catches planted AI-era bugs before a release ships. - Agent harness installer : ubon agent install --all --write can generate Cursor, Claude Code, Codex, pre-commit, GitHub Actions, and .gitignore harness files from one dry-run-first workflow. - Expanded Cursor hooks : t","default_branch":null,"files":null,"tree":[],"storefront":"/r/luisfer","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/luisfer/ubon/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}