Free security & privacy scanner for AI-coded apps. 699 rules, 76 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your AI-generated app for l
🔒 Security scanner + AI agent firewall for vibe-coded apps.
Scan AI-generated code for leaked keys, SQLi, prompt injection, and uncapped agent loops. 764 rules · 82 MCP tools · 18 languages · 10 compliance frameworks 100% offline · Zero telemetry · Zero runtime dependencies · Free forever.
Captured against a test project with a planted sklive Stripe key.
🛡️ Features • ⚡ Quick Start • 📊 Benchmark • ⌨️ Commands • 🌐 Website • ❓ Why • ⚖️ Limits
AI coding tools ship fast but skip security. Most devs vibe-code a prototype and forget to harden it. VibeGuard raises the floor — one command, 5 seconds, no account, no telemetry.
One-command layered protection (daemon + hooks + shell guard + proxy):
15 AI clients supported — Claude Code, Cursor, Windsurf, Codex CLI, Antigravity, Continue, Cline, Aider, Gemini CLI, Roo Code, OpenHands, VS Code, Copilot CLI, Amazon Q, Sourcegraph Cody. Install: vibeguard install.
Flags 50+ secret types — OpenAI, AWS, GitHub, Stripe, Slack, Firebase, GCP, Twilio, SendGrid, npm, Mailgun, Resend, Telegram — and tells you to move them to process.env.
Detects missing RLS, fake RLS policies (USING (true)), and service-role keys in client components.
AST taint analysis traces req.body.id through template literals to query() — confirmed dataflow, not a regex guess.
Catches user input injected into the system role — the root cause of most prompt injection attacks.
From the project README.
Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:
[](https://mcp.liqiwa.com/s/yagyeshVyas--VibeGuard.html)
MCP security scanner — vet a Model Context Protocol server before you add it to Claude Code, Cursor, or Windsurf. Grades it A–F, catching credential theft, tool-poisoning, and install-script payloads
howshannon/trust-issuesAdversarial security review for AI skills, repos, MCP servers, and packages before you install them. A read-only scanner plus a five-persona reasoning pass, ending in a GO / GO WITH MITIGATIONS / NO-G
frangelbarrera/code-review-agent-mcpAI code review agent MCP server. Reviews code like a kernel maintainer: blunt, technical, no sugarcoating. Detects bugs + OWASP Top 10 security vulnerabilities. 4 harshness levels. Anti-RLHF.
Octolabo/malskannerScan a repo for hidden prompt-injection before your AI agent trusts it — CLI, MCP server & GitHub Action. Run: npx malskanner <repo>. 0 false positives across 5,620 files.
flankerhqd/cyvisguardSecurity control plane for AI agents — identity and delegation, capability policy, data-flow taint and a live audit trail, enforced over MCP. Guards a real Claude Code end to end.
pranee54/AgentDoctorLocal CLI that audits coding-agent configuration for security, instructions, context, and MCP — no API key or code upload by default.
The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.