ComingUp ComingUp
VibeScan - Security scanning for vibe-coded apps

VibeScan - Security scanning for vibe-coded apps

VibeScan is security scanning built for AI-generated code and live endpoints

Aug 21, 2026 Security & Privacy
ai generated code code security devsecops security vulnerability scanning

Gallery

VibeScan - Security scanning for vibe-coded apps

About

Apps built with Claude Code, Cursor, Bolt, and Lovable ship the same predictable security mistakes, because AI coding tools optimize for "make it work," not "make it secure." VibeScan is positioned against that specific failure mode — not a generic pentest tool competing on features with Snyk or Detectify.Two independently-gated scan products, both built and live:Live website scan — DNS TXT domain-ownership verification (same pattern as Google Search Console) gates a passive/light-active scanner: security headers, TLS config, exposed paths, outdated JS libraries.Repository scan — GitHub OAuth connects public or private repos; runs Semgrep, Bandit, osv-scanner, and Gitleaks and returns real findings.Also ships as an MCP server — connects to Claude Code, Claude Desktop, Cursor, or any MCP-compatible agent, so a coding agent can check known issues and trigger scans mid-session. This is a real distribution edge as agent-driven development grows.

Comments (0)

No comments yet. Be the first to comment!