vibe-security-check
The feature works. Did the guard around it ship too?
A defensive, read-only-by-default audit for rapidly built web and SaaS apps. It traces auth, tenant isolation, data rules, storage, paid endpoints, URL fetchers, payments, uploads, and AI tools from untrusted input to side effect—then reports only evidence-backed findings.
- 01cross-user access
- 02open data rules
- 03client-side authority
- 04runaway spend
- 05broken tokens
- 06leaky RLS policies
- 07public storage
- 08pre-auth abuse
- 09server-side URL fetches
- 10AI tool injection
Then it widens to secrets, sessions, input handling, webhooks, uploads, supply chain, logging, and production configuration.