Item logo image for VibeGuard

VibeGuard

Item media 1 (screenshot) for VibeGuard

Overview

Security diagnostics for AI-generated code, in any browser tab.

VibeGuard scans the source code you encounter on the web for security issues specific to AI-generated code — stub bodies, hardcoded secrets, weak crypto, SQL/command injection, missing authentication, debug flags left on, mock data leaking into production paths, and more. Open the side panel on any tab, paste a snippet (or run "Extract code blocks from page" on a GitHub PR / Stack Overflow / blog post / chat window) and get findings annotated with severity, why-it-matters, and how-to-fix. You can also right-click any selected code → "Scan with VibeGuard". Everything runs locally in your browser. No code is sent to any server. The analyzer is the same engine used by the VibeGuard CLI and GitHub Action, so verdicts stay consistent across editor, browser, and CI. ▼ What it detects (30 built-in rules) - Injection: SQL / command / NoSQL / template / SSRF / open redirect / unsafe eval - Auth & secrets: hardcoded tokens, weak JWT secrets, missing auth checks, dummy credentials, disabled TLS verification - Crypto: MD5/SHA-1, ECB mode, weak random - AI-code heuristics (VibeGuard's specialty): - stub function bodies (throw NotImplementedError, return null + TODO) - placeholder emails (example.com, test.com, foo.bar) - mock data on production paths - debug=true flags - "for now" / "not for production" comments left in code - empty validators that always return true ▼ Privacy - 100% local analysis. Code never leaves your browser. - No telemetry, no analytics, no remote calls. - Works fully offline. ▼ Open source MIT-licensed. Source, rules, and roadmap: https://github.com/YUTAKONDO1205/VibeGuard ──────────────────────────── VibeGuard は、ブラウザ上で目にするソースコードに対して、AI 生成コード特有の セキュリティ問題を検出する拡張機能です。スタブ実装、ハードコードされた秘密情報、 弱い暗号、SQL/コマンドインジェクション、認証チェック漏れ、デバッグフラグの 残置、テスト用モックデータの本番混入などを検出します。 任意のタブでサイドパネルを開き、コードを貼り付けるか、ページから自動抽出するか、 選択範囲を右クリックして「Scan with VibeGuard」を実行するだけです。検出結果には 深刻度・なぜ問題か・どう直すかが付きます。 すべての解析はブラウザ内で完結します。コードは外部に一切送信されません。同じ 解析エンジンが VibeGuard CLI / GitHub Action でも使われており、エディタ・ ブラウザ・CI の判定基準がブレません。 ▼ 検出ルール(30 種類) - インジェクション: SQL / コマンド / NoSQL / テンプレート / SSRF / open redirect / unsafe eval - 認証 & 秘密情報: ハードコードされたトークン、弱い JWT 秘密鍵、認証チェック漏れ、 ダミー資格情報、TLS 検証無効化 - 暗号: MD5/SHA-1、ECB モード、弱い乱数 - AI 生成コード特化(VibeGuard の独自強み): - スタブ実装(NotImplementedError / TODO 付き return null) - プレースホルダーメール(example.com、test.com、foo.bar) - 本番経路に紛れ込んだモックデータ - debug=true フラグ - 「for now」「not for production」コメントの残置 - 常に true を返す空バリデータ ▼ プライバシー - 完全ローカル解析。コードはブラウザの外に出ません - テレメトリ・アナリティクス・外部通信なし - オフラインで動作します ▼ オープンソース(MIT License) ソース・ルール一覧・ロードマップ: https://github.com/YUTAKONDO1205/VibeGuard

Details

  • Version
    0.1.3
  • Updated
    May 30, 2026
  • Offered by
    kondo.yuta.02
  • Size
    74.81KiB
  • Languages
    English (United States)
  • Developer
    近藤悠太
    西条末広町4−53 ラプリムヴェール C102 東広島市, 広島県 739-0004 JP
    Email
    kondo.yuta.02@gmail.com
    Phone
    +81 80-9260-3694
  • Trader
    This developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Related

SQL Injection Checker

5.0

Professional security testing tool for detecting SQL injection vulnerabilities

HAVI – Human-Agent Visual Interface

0.0

Capture visual annotations on any web page; your AI coding agent pulls the full context in via MCP.

Shortcuts Scanner

0.0

View, inspect, download and perform AI-powered security analysis for Apple Shortcuts from iCloud.com

PwnDeck Scanner — Website Security & Privacy

5.0

Instant security & privacy audit for any site: headers, cookies, trackers, tech stack, vulnerable JS libraries.

SecuriScan - Web Security Analyzer

0.0

Lightweight security scanner that analyzes websites for common vulnerabilities, trackers, and security misconfigurations

ASS - ASCII Smuggling Surfacer

5.0

Detect invisible Unicode steganography & smuggling attacks in web pages

Pixel Auditor: Tag, PII & Consent Mode Inspector

5.0

Inspect every tracking pixel firing on a page: tag IDs, event payloads, consent-mode signals, cookies, and PII leaks.

SHIELD CryptoGuard — Web3 Antivirus

0.0

AI-powered Web3 security. Blocks phishing, detects honeypots, intercepts malicious approvals before your wallet signs anything.

Extension Auditor Pro - Assess Risk & Improve Browser Security Posture

5.0

Assess, and monitor browser extensions for security and privacy risks. Improve your Browser Security Posture and Stay Safe Oonline.

Real Browser MCP

3.5

Let AI agents control your real browser - your tabs, your sessions, your logins

CRX Extractor Pro

0.0

Download and extract extensions from Chrome, Edge, Firefox, and Opera. Advanced full-screen source code viewer included.

Tyre Kicker - Security Scanner

0.0

Offline security scanner. Detect API keys, CVEs, config issues. No external API calls. For authorized testing only.

SQL Injection Checker

5.0

Professional security testing tool for detecting SQL injection vulnerabilities

HAVI – Human-Agent Visual Interface

0.0

Capture visual annotations on any web page; your AI coding agent pulls the full context in via MCP.

Shortcuts Scanner

0.0

View, inspect, download and perform AI-powered security analysis for Apple Shortcuts from iCloud.com

PwnDeck Scanner — Website Security & Privacy

5.0

Instant security & privacy audit for any site: headers, cookies, trackers, tech stack, vulnerable JS libraries.

SecuriScan - Web Security Analyzer

0.0

Lightweight security scanner that analyzes websites for common vulnerabilities, trackers, and security misconfigurations

ASS - ASCII Smuggling Surfacer

5.0

Detect invisible Unicode steganography & smuggling attacks in web pages

Pixel Auditor: Tag, PII & Consent Mode Inspector

5.0

Inspect every tracking pixel firing on a page: tag IDs, event payloads, consent-mode signals, cookies, and PII leaks.

SHIELD CryptoGuard — Web3 Antivirus

0.0

AI-powered Web3 security. Blocks phishing, detects honeypots, intercepts malicious approvals before your wallet signs anything.

Google apps