VibeGuard
Overview
Security diagnostics for AI-generated code, in any browser tab.
VibeGuard scans the source code you encounter on the web for security issues specific to AI-generated code — stub bodies, hallucinated dependencies, hardcoded secrets, weak crypto, SQL/command injection, missing authentication, debug flags left on, mock data leaking into production paths, and more. Open the side panel on any tab, paste a snippet (or run "Extract code blocks from page" on a GitHub PR / Stack Overflow / blog post / chat window) and get findings annotated with severity, why-it-matters, and how-to-fix. You can also right-click any selected code → "Scan with VibeGuard". Everything runs locally in your browser. No code is sent to any server. The analyzer is the same engine used by the VibeGuard CLI and GitHub Action, so verdicts stay consistent across editor, browser, and CI. ▼ What it detects (72 built-in rules) - Injection: SQL string concatenation, shell/command execution with dynamic args, eval(), unsafe deserialization (pickle / yaml.load / unserialize), innerHTML assignment, path traversal, prototype-polluting merges, XXE, mass assignment, dynamic include/require - Auth & CSRF: authentication bypass behind DEBUG, dummy or placeholder credentials, disabled TLS certificate verification, disabled CSRF protection, session cookies missing secure / httpOnly - Secrets: AWS access keys, GitHub personal access tokens, embedded PEM private keys, likely API keys in literals - Crypto: MD5 / SHA-1 in a security context, non-cryptographic randomness used for tokens and IDs, cleartext http:// endpoints - Framework: Django DEBUG = True, Flask debug server, wildcard CORS, Go servers listening on all interfaces without TLS - AI-code heuristics (VibeGuard's specialty): - hallucinated dependencies — imports of packages that do not exist - stub function bodies (not-implemented / TODO placeholders) - validators and sanitizers with a passthrough body - mock / dummy identifiers and security leftovers outside test paths - placeholder email addresses, debug flags hardcoded ON - "for now" / "not for production" comments left in code - Embedded C / C++ / Arduino: memory safety (gets, strcpy/strcat/sprintf, double free, use-after-free), hardcoded Wi-Fi credentials, static BLE pairing passkeys, firmware debug and auth-bypass flags, credentials printed to serial, forbidden calls inside interrupt handlers - Design smells: over-long security methods, primitive role checks, security "Swiss army knife" modules Languages: Python, JavaScript / TypeScript, Java, Go, Ruby, PHP, C / C++ / Arduino. ▼ Privacy - 100% local analysis. Code never leaves your browser. - No telemetry, no analytics, no remote calls. - Works fully offline. ▼ Open source MIT-licensed. Source, rules, and roadmap: https://github.com/YUTAKONDO1205/VibeGuard ──────────────────────────── VibeGuard は、ブラウザ上で目にするソースコードに対して、AI 生成コード特有の セキュリティ問題を検出する拡張機能です。スタブ実装、存在しないパッケージへの 依存(幻覚依存)、ハードコードされた秘密情報、弱い暗号、SQL/コマンド インジェクション、認証チェック漏れ、デバッグフラグの残置、テスト用モックデータの 本番混入などを検出します。 任意のタブでサイドパネルを開き、コードを貼り付けるか、ページから自動抽出するか、 選択範囲を右クリックして「Scan with VibeGuard」を実行するだけです。検出結果には 深刻度・なぜ問題か・どう直すかが付きます。 すべての解析はブラウザ内で完結します。コードは外部に一切送信されません。同じ 解析エンジンが VibeGuard CLI / GitHub Action でも使われており、エディタ・ ブラウザ・CI の判定基準がブレません。 ▼ 検出ルール(72 種類) - インジェクション: SQL 文字列連結、シェル/コマンド実行への動的引数、eval()、 安全でないデシリアライズ(pickle / yaml.load / unserialize)、innerHTML 代入、 パス連結、プロトタイプ汚染マージ、XXE、マスアサインメント、動的 include - 認証 & CSRF: DEBUG 時の認証バイパス、ダミー/プレースホルダー資格情報、 TLS 証明書検証の無効化、CSRF 保護の無効化、secure / httpOnly 欠落の セッション Cookie - 秘密情報: AWS アクセスキー、GitHub パーソナルアクセストークン、埋め込み PEM 秘密鍵、リテラル中の API キー - 暗号: セキュリティ文脈での MD5 / SHA-1、トークンや ID への非暗号論的乱数、 平文 http:// エンドポイント - フレームワーク: Django DEBUG = True、Flask デバッグサーバ、ワイルドカード CORS、TLS なしで全インターフェースを待ち受ける Go サーバ - AI 生成コード特化(VibeGuard の独自強み): - 幻覚依存 — 実在しないパッケージの import - スタブ実装(未実装 / TODO プレースホルダー) - 素通しの本体を持つバリデータ・サニタイザ - テスト経路外のモック/ダミー識別子とセキュリティ残骸 - プレースホルダーメールアドレス、ON 固定のデバッグフラグ - 「for now」「not for production」コメントの残置 - 組込み C / C++ / Arduino: メモリ安全性(gets、strcpy/strcat/sprintf、 二重 free、解放後使用)、Wi-Fi 認証情報のハードコード、固定 BLE ペアリング パスキー、ファームウェアのデバッグ/認証バイパスフラグ、シリアルへの資格情報 出力、割り込みハンドラ内の禁止呼び出し - 設計スメル: 長すぎるセキュリティメソッド、素朴なロール判定、セキュリティの 「万能ナイフ」モジュール 対応言語: Python、JavaScript / TypeScript、Java、Go、Ruby、PHP、C / C++ / Arduino。 ▼ プライバシー - 完全ローカル解析。コードはブラウザの外に出ません - テレメトリ・アナリティクス・外部通信なし - オフラインで動作します ▼ オープンソース(MIT License) ソース・ルール一覧・ロードマップ: https://github.com/YUTAKONDO1205/VibeGuard
0 out of 5No ratings
Details
- Version0.3.6
- UpdatedAugust 17, 2026
- Offered bykondo.yuta.02
- Size315KiB
- LanguagesEnglish (United States)
- Developer近藤悠太
西条末広町4−53 ラプリムヴェール C102 東広島市, 広島県 739-0004 JPEmail
kondo.yuta.02@gmail.comPhone
+81 80-9260-3694 - TraderThis developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site