📡 MCP Radar

yagyeshVyas/VibeGuard

Free security & privacy scanner for AI-coded apps. 699 rules, 76 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your AI-generated app for l

3 stars
1 forks
JavaScript
momentum ▲ 8.0
created 2026-07-11
on radar since 2026-07-16
ai-coding-assistantai-securitycicdclaude-codecode-scannercursordeveloper-toolsllm-securitymcpmcp-serverowasppre-commitprompt-injectionsarifsastsecret-scanningsecurity-scannerstatic-analysissupply-chain-securityvibe-coding
View on GitHub ↗Homepage ↗

About VibeGuard

🔒 Security scanner + AI agent firewall for vibe-coded apps.

Scan AI-generated code for leaked keys, SQLi, prompt injection, and uncapped agent loops. 764 rules · 82 MCP tools · 18 languages · 10 compliance frameworks 100% offline · Zero telemetry · Zero runtime dependencies · Free forever.

Captured against a test project with a planted sklive Stripe key.

🛡️ Features • ⚡ Quick Start • 📊 Benchmark • ⌨️ Commands • 🌐 Website • ❓ Why • ⚖️ Limits

AI coding tools ship fast but skip security. Most devs vibe-code a prototype and forget to harden it. VibeGuard raises the floor — one command, 5 seconds, no account, no telemetry.

One-command layered protection (daemon + hooks + shell guard + proxy):

15 AI clients supported — Claude Code, Cursor, Windsurf, Codex CLI, Antigravity, Continue, Cline, Aider, Gemini CLI, Roo Code, OpenHands, VS Code, Copilot CLI, Amazon Q, Sourcegraph Cody. Install: vibeguard install.

Flags 50+ secret types — OpenAI, AWS, GitHub, Stripe, Slack, Firebase, GCP, Twilio, SendGrid, npm, Mailgun, Resend, Telegram — and tells you to move them to process.env.

Detects missing RLS, fake RLS policies (USING (true)), and service-role keys in client components.

AST taint analysis traces req.body.id through template literals to query() — confirmed dataflow, not a regex guess.

Catches user input injected into the system role — the root cause of most prompt injection attacks.

From the project README.

Maintaining this server?

Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:

[![On MCP Radar](https://mcp.liqiwa.com/badge.svg)](https://mcp.liqiwa.com/s/yagyeshVyas--VibeGuard.html)

Related MCP servers

12122J/mcpvet

MCP security scanner — vet a Model Context Protocol server before you add it to Claude Code, Cursor, or Windsurf. Grades it A–F, catching credential theft, tool-poisoning, and install-script payloads

⭐ 10JavaScript
howshannon/trust-issues

Adversarial security review for AI skills, repos, MCP servers, and packages before you install them. A read-only scanner plus a five-persona reasoning pass, ending in a GO / GO WITH MITIGATIONS / NO-G

⭐ 5Shell
frangelbarrera/code-review-agent-mcp

AI code review agent MCP server. Reviews code like a kernel maintainer: blunt, technical, no sugarcoating. Detects bugs + OWASP Top 10 security vulnerabilities. 4 harshness levels. Anti-RLHF.

⭐ 5Python
Octolabo/malskanner

Scan a repo for hidden prompt-injection before your AI agent trusts it — CLI, MCP server & GitHub Action. Run: npx malskanner <repo>. 0 false positives across 5,620 files.

⭐ 5TypeScript
flankerhqd/cyvisguard

Security control plane for AI agents — identity and delegation, capability policy, data-flow taint and a live audit trail, enforced over MCP. Guards a real Claude Code end to end.

⭐ 30TypeScript
pranee54/AgentDoctor

Local CLI that audits coding-agent configuration for security, instructions, context, and MCP — no API key or code upload by default.

⭐ 10TypeScript

📬 Get the weekly radar in your inbox

The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.