Metadata-Version: 2.4
Name: vibesec
Version: 0.4.0
Summary: Security scanner for AI-generated code
Author-email: Ayush Khati <ayushiskhati305@gmail.com>
License: MIT License
        
        Copyright (c) 2026 Ayush Khati
        
        Permission is hereby granted, free of charge, to any person obtaining a copy
        of this software and associated documentation files (the "Software"), to deal
        in the Software without restriction, including without limitation the rights
        to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
        copies of the Software, and to permit persons to whom the Software is
        furnished to do so, subject to the following conditions:
        
        The above copyright notice and this permission notice shall be included in all
        copies or substantial portions of the Software.
        
        THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
        IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
        FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
        AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
        LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
        OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
        SOFTWARE.
        
Project-URL: Homepage, https://github.com/AyushkhatiDev/vibesec
Project-URL: Bug Tracker, https://github.com/AyushkhatiDev/vibesec/issues
Classifier: Programming Language :: Python :: 3
Classifier: License :: OSI Approved :: MIT License
Classifier: Operating System :: OS Independent
Classifier: Topic :: Security
Classifier: Topic :: Software Development :: Quality Assurance
Requires-Python: >=3.8
Description-Content-Type: text/markdown
License-File: LICENSE
Requires-Dist: click>=8.0
Requires-Dist: rich>=13.0
Requires-Dist: requests>=2.28
Requires-Dist: groq>=0.4.0
Requires-Dist: python-dotenv>=1.0.0
Dynamic: license-file

# 🔒 VibeSec

**Security scanner for AI-generated code.**

[![VibeSec v0.3.0](https://img.shields.io/badge/vibesec-v0.3.0-blue)](https://pypi.org/project/vibesec/)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)
[![Python 3.8+](https://img.shields.io/badge/python-3.8+-blue.svg)](https://www.python.org/downloads/)
[![GitHub stars](https://img.shields.io/github/stars/AyushkhatiDev/vibesec?style=social)](https://github.com/AyushkhatiDev/vibesec)

45% of AI-generated code ships with critical vulnerabilities. Cursor, Claude Code, Bolt, and Lovable generate insecure patterns that existing tools miss. VibeSec catches them before you deploy.

```
$ vibesec scan ./my-cursor-app

  VibeSec v0.2.0 — AI-Generated Code Security Scanner

  ● CRITICAL    7 findings
  ● HIGH        2 findings

  CRITICAL — Hardcoded Secret
  File: src/lib/supabase.ts  Line: 12
  Found: SUPABASE_SERVICE_KEY hardcoded in source code
  Fix:   Move to environment variables. Never commit secrets to git.

  CRITICAL — Supabase RLS Disabled
  File: supabase/migrations/001_init.sql  Line: 34
  Found: ALTER TABLE users DISABLE ROW LEVEL SECURITY
  Fix:   Enable RLS + add user isolation policies.

  9 findings in ./my-cursor-app
```

---

## Why VibeSec

Existing tools like Semgrep, Snyk, and CodeQL are great — but they were built for human-written code. AI tools generate specific anti-patterns that these scanners miss:

| Pattern | Semgrep | Snyk | VibeSec |
|---|---|---|---|
| Hardcoded secrets | ✓ | ✓ | ✓ |
| Supabase RLS disabled | ✗ | ✗ | ✓ |
| Hallucinated npm packages | ✗ | ✗ | ✓ |
| Missing auth on scaffolded routes | Partial | ✗ | ✓ |
| Source map exposure in build config | ✗ | ✗ | ✓ |
| AI-specific JWT misuse | ✗ | ✗ | ✓ |

---

## Install

```bash
pip install vibesec
```

---

## Usage

**Scan a directory:**
```bash
vibesec scan ./my-project
```

**Scan and get AI-powered fix suggestions:**
```bash
vibesec scan ./my-project --fix
```

**Export results as JSON (for CI/CD):**
```bash
vibesec scan ./my-project --output json
```

**Export as SARIF (for GitHub Security tab):**
```bash
vibesec scan ./my-project --output sarif
```

**Custom SARIF output path:**
```bash
vibesec scan ./my-project --output sarif --sarif-output results.sarif
```

**Filter by severity:**
```bash
vibesec scan ./my-project --severity critical
```

**Ignore specific checks:**
```bash
vibesec scan ./my-project --ignore rls,cors
```

---

## What VibeSec Checks

### 🔴 CRITICAL

**1. Hardcoded Secrets**
API keys, passwords, tokens, and database URLs hardcoded in source files. LLMs replicate tutorial patterns where secrets are hardcoded.

```python
# VibeSec catches this
api_key = "sk-abc123..."
SUPABASE_SERVICE_KEY = "eyJhbGci..."
stripe_secret = "sk_live_..."
```

**2. Supabase RLS Disabled**
Row Level Security disabled — any authenticated user can read or modify all data. LLMs skip RLS to make queries work quickly in scaffolding.

```sql
-- VibeSec catches this
ALTER TABLE users DISABLE ROW LEVEL SECURITY;
```

**3. SQL Injection Risk**
AST-based taint analysis tracks user-controlled input from 30+ Flask/Django/FastAPI
sources through Python call graphs to database sinks. Catches tainted f-strings,
string concatenation, and format interpolation — while ignoring parameterized queries
and sanitized values.

```python
# VibeSec catches this — tainted input reaches SQL sink
query = f"SELECT * FROM users WHERE id = {request.args.get('id')}"
cursor.execute(query)

# VibeSec ignores this — parameterized, safe
cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,))
```

### 🟡 HIGH

**4. Missing Route Authentication**
Admin and sensitive API routes scaffolded without authentication middleware. LLMs build the happy path without thinking about access control.

**5. Hallucinated Packages**
npm packages that don't exist — a typosquatting attack surface. LLMs generate plausible-sounding package names that aren't real.

```json
// VibeSec catches this
"react-auth-handler": "^1.0.0",
"supabase-helpers": "^2.1.0"
```

**6. Source Map Exposure**
Build config exposes full source code via `.map` files in production.

**7. Unsafe JWT Handling** — `none` algorithm, verification disabled, or tokens stored in web storage

**8. Client-Side Role Trust** — Admin checks done using client-controlled values (localStorage/URL params)

**9. Insecure Flask Configuration** — DEBUG mode, hardcoded SECRET_KEY, or weak fallback key

**10. Credentials in Environment File** — Real API keys or DB URLs committed in `.env`

### 🟠 MEDIUM

**11. Unsafe HTML Injection (XSS)** — `dangerouslySetInnerHTML`, `innerHTML`, or `eval` with dynamic input

**12. Missing Webhook Verification** — Stripe/GitHub webhooks without signature check

**13. Permissive CORS Configuration** — Wildcard CORS with credentials enabled

---

## GitHub Actions Integration

Add VibeSec to your CI/CD pipeline with SARIF output — findings appear directly in GitHub's **Security tab** as inline code annotations:

```yaml
# .github/workflows/vibesec.yml
name: VibeSec Security Scan

on:
  push:
    branches: [main, master]
  pull_request:
    branches: [main, master]

permissions:
  security-events: write
  contents: read

jobs:
  vibesec:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-python@v5
        with:
          python-version: '3.11'
      - name: Install VibeSec
        run: pip install .
      - name: Run VibeSec Scan
        run: vibesec scan . --output sarif --sarif-output vibesec-results.sarif
        continue-on-error: true
      - name: Upload SARIF to GitHub Security
        uses: github/codeql-action/upload-sarif@v4
        if: always()
        with:
          sarif_file: vibesec-results.sarif
          category: vibesec
```

> **Note:** The `upload-sarif` action requires GitHub Advanced Security to be enabled (free for public repositories).

---

## GitHub Security Tab

When using SARIF output with the GitHub Action above, VibeSec findings appear natively in:

- **Security → Code scanning alerts** — filterable dashboard of all findings
- **Pull request annotations** — inline warnings on the exact lines with vulnerabilities
- **Security overview** — aggregate view across your organization

Each finding includes the rule ID (e.g. `VS001`), severity level, the offending code snippet, and a fix suggestion.

---

## Development

```bash
git clone https://github.com/AyushkhatiDev/vibesec
cd vibesec
python -m venv venv
source venv/bin/activate
pip install -e ".[dev]"
pytest tests/
```

---

## Contributing

VibeSec is open source and contributions are welcome.

**Adding a new rule:**
1. Create `vibesec/rules/your_rule.py`
2. Implement `check_your_rule(file_path, content) -> list[dict]`
3. Register it in `vibesec/rules/__init__.py`
4. Add test cases in `tests/corpus/`
5. Open a PR

Each finding must return:
```python
{
    "rule": "Rule Name",
    "severity": "CRITICAL|HIGH|MEDIUM|LOW",
    "file": file_path,
    "line": line_number,
    "message": "What was found",
    "fix_hint": "How to fix it",
    "code_snippet": "offending line"
}
```

See [CONTRIBUTING.md](CONTRIBUTING.md) for full guide.

---

## Roadmap

- [x] Secrets detection
- [x] Supabase RLS checker
- [x] Missing auth on routes
- [x] Hallucinated package detector
- [x] Source map exposure
- [x] JWT misuse rules
- [x] dangerouslySetInnerHTML XSS detection
- [x] Client-side role trust
- [x] Webhook verification
- [x] Permissive CORS
- [x] Flask SECRET_KEY and debug mode detection
- [x] Credentials in .env files
- [x] SQL injection patterns
- [x] AST-based taint analysis engine (Python)
- [x] 74 automated tests with true positive/negative validation
- [x] .vibesecignore support
- [x] AI-powered fix suggestions (Groq)
- [x] SARIF output for GitHub Security tab
- [x] GitHub Action with SARIF upload
- [ ] GitHub Action marketplace listing
- [ ] Scan public GitHub repos by URL
- [ ] Web app (paste URL → get report)
- [ ] VS Code extension

---

## Built By

[Ayush Khati](https://github.com/AyushkhatiDev) — BCA student building real tools for real problems.

Found a bug? [Open an issue](https://github.com/AyushkhatiDev/vibesec/issues).
Want a rule added? [Start a discussion](https://github.com/AyushkhatiDev/vibesec/discussions).

---

## License

MIT — free to use, modify, and distribute.

---

<p align="center">
  <sub>Built because 45% of vibe-coded apps ship with critical vulnerabilities. Someone had to fix that.</sub>
</p>
