Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

VibeGuard 🛡️

The security linter built for AI-generated code.

Python 3.10+ License: MIT Built by zeroFhacker


The Problem

AI coding assistants — GitHub Copilot, Cursor, Claude, ChatGPT — write code fast. Really fast. Faster than any security review can keep up with.

The problem is they also confidently produce the same security mistakes over and over. Not because they are bad tools. Because they were trained on millions of code examples — and millions of those examples had security vulnerabilities in them.

The exact mistakes AI coding assistants make repeatedly:

  • SQL queries built with string concatenation instead of parameterized queries
  • Secrets and API keys hardcoded directly into source files
  • User input passed to eval(), exec(), subprocess.shell=True without validation
  • JWT tokens verified without checking the algorithm — the alg:none bypass
  • XML parsers configured to allow external entities — XXE vulnerabilities
  • Insecure random number generation used for security-sensitive values
  • Path traversal — user-controlled file paths with no sanitization
  • CORS configured to accept any origin
  • Debug mode left enabled in production configuration
  • Pickle deserialization of untrusted data — remote code execution

Traditional linters like Bandit and Semgrep catch some of these. But they use generic rules that were not built around the specific patterns AI tools produce. VibeGuard is different — every rule was written by studying actual AI-generated code and cataloguing the exact vulnerability patterns these tools produce.


Demo

$ vibeguard scan --path ./my-ai-generated-project

[*] VibeGuard v1.0.0 — AI-Generated Code Security Linter
[*] Scanning: ./my-ai-generated-project
[*] Running 47 AI-pattern rules...

app/database.py:34     CRITICAL  SQL_INJECTION      f-string used in SQL query — classic Copilot pattern
app/auth.py:12         CRITICAL  HARDCODED_SECRET   API key assigned to variable — detected by entropy
app/utils.py:89        HIGH      COMMAND_INJECTION   subprocess called with shell=True + user input
app/api.py:156         HIGH      JWT_ALG_NONE        JWT decoded without algorithm verification
config/settings.py:8   HIGH      DEBUG_PRODUCTION   DEBUG=True in production settings file
app/files.py:44        MEDIUM    PATH_TRAVERSAL      User input used in file path without sanitization
app/xml_parser.py:23   MEDIUM    XXE_INJECTION       XML parser allows external entities

[*] Grade: D  (7 findings — 2 critical, 3 high, 2 medium)
[*] Report saved to vibeguard-report.json

Fix these first:
  app/database.py:34 → Use cursor.execute(query, params) instead of f-strings
  app/auth.py:12     → Move to environment variable: os.environ.get('API_KEY')

What Makes VibeGuard Different From Bandit or Semgrep?

Feature VibeGuard Bandit Semgrep
Rules built from AI code patterns
Letter grade (A–F)
Plain English fix for every finding Partial Partial
Detects AI-specific anti-patterns
Zero configuration to start
CI/CD mode with exit codes
VS Code extension Roadmap

Who Is This For?

  • Developers using Copilot, Cursor, Claude, or ChatGPT to write code
  • Security engineers reviewing AI-generated pull requests
  • Engineering teams who have adopted AI coding tools and want automated security checks
  • DevSecOps teams who want AI-specific security gates in their CI/CD pipeline
  • Students learning about the security implications of AI-generated code

Before You Start

Check Python is installed

python3 --version

You need version 3.10 or higher.

Check Git is installed

git --version

Installation

# Clone the repo
git clone https://github.com/zeroFhacker/vibeguard.git
cd vibeguard

# Create virtual environment
python3 -m venv venv
source venv/bin/activate   # Windows: venv\Scripts\activate

# Install
pip install -r requirements.txt

Usage

Scan a directory

PYTHONPATH=. python -m vibeguard.cli scan --path ./my-project

Scan a single file

PYTHONPATH=. python -m vibeguard.cli scan --path ./app/database.py

CI mode — exits with code 1 if findings above threshold

PYTHONPATH=. python -m vibeguard.cli scan --path . --ci --fail-on high

Show only critical findings

PYTHONPATH=. python -m vibeguard.cli scan --path . --severity critical

Save report

PYTHONPATH=. python -m vibeguard.cli scan --path . --output report.json

List all rules

PYTHONPATH=. python -m vibeguard.cli rules list

The Rule Library — 47 AI-Pattern Rules

Category 1: Injection (AI tools love string concatenation)

  • SQL injection via f-string or concatenation
  • Command injection via shell=True
  • LDAP injection
  • XPath injection
  • Template injection

Category 2: Secrets (AI tools hardcode everything)

  • API keys assigned to variables
  • Hardcoded passwords in source
  • AWS/GCP/Azure credentials in code
  • Private keys in source files
  • Database connection strings with credentials

Category 3: Authentication (AI tools skip the hard parts)

  • JWT decoded without algorithm verification
  • JWT secret hardcoded
  • Weak session secret
  • Missing authentication on sensitive endpoints
  • Insecure password hashing (MD5, SHA1)

Category 4: Input Validation (AI tools trust user input)

  • Path traversal via user-controlled file paths
  • XML external entity injection
  • Eval/exec with user input
  • Pickle deserialization of untrusted data
  • YAML load instead of safe_load

Category 5: Configuration (AI tools use development defaults)

  • Debug mode enabled in production
  • CORS wildcard origin
  • Insecure cookie settings (no HttpOnly, no Secure)
  • Weak TLS configuration
  • Default admin credentials

Category 6: Cryptography (AI tools use deprecated functions)

  • MD5 used for security-sensitive hashing
  • SHA1 used for security-sensitive hashing
  • Weak random (random module) for security values
  • ECB mode encryption
  • Hardcoded encryption key

GitHub Actions Integration

Add to .github/workflows/security.yml:

name: VibeGuard Security Scan

on: [push, pull_request]

jobs:
  vibeguard:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-python@v4
        with:
          python-version: '3.11'
      - run: pip install -r requirements.txt
      - name: Run VibeGuard
        run: |
          PYTHONPATH=. python -m vibeguard.cli scan \
            --path . \
            --ci \
            --fail-on high \
            --output vibeguard-report.json
      - name: Upload report
        uses: actions/upload-artifact@v4
        with:
          name: vibeguard-security-report
          path: vibeguard-report.json

Understanding the Grade

Grade Score What It Means
A 90–100 Excellent — no high or critical findings
B 75–89 Good — minor issues only
C 60–74 Needs attention — several medium findings
D 40–59 Poor — high severity findings present
F 0–39 Critical — immediate action required

Contributing

New AI-pattern rules are always welcome. To add a rule:

  1. Add a RulePattern to vibeguard/rules/patterns.py
  2. Write the regex or AST check
  3. Include: name, description, severity, AI tool that commonly produces this, plain English fix
  4. Add a test in tests/test_rules.py

See CONTRIBUTING.md for full guidance.


License

MIT — see LICENSE


Built by zeroFhacker

Part of the open-source security toolkit at github.com/zeroFhacker

About

Security linter for AI-generated code: catches the exact vulnerabilities Copilot, Cursor and ChatGPT repeatedly produce. SQL injection, hardcoded secrets, JWT bypass, command injection and 15+ more rules. Grade A–F. Zero config. CI/CD ready.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages