Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
vibegate — Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance. | Kitploit
Tools/GitHubGitHub/themiddleblue/vibegate
Static AnalysisVulnerability ScannersCode AnalysisDevSecOpsSupply Chain SecurityMisconfigurationLearning & EducationAI Security
GitHubthemiddleblue/vibegate

vibegate

Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance.

View Repository
81202 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

VibeGate logo

CI License: MIT

A security checkpoint for AI coding tools. It looks at every file an AI assistant writes, and stops the dangerous ones before they hit disk.

What problem does this solve?

AI coding assistants (Claude Code, Codex, …) write code fast — including code that handles things like passwords, emails, API keys, or raw user input. It's easy for an assistant to wire that data straight into a database query, a shell command, or an HTTP response without thinking about security.

VibeGate sits between the assistant and your filesystem. Every time the assistant tries to write or edit a file, VibeGate scans the new code first:

  • Finds user-controlled input in the code (using Semgrep)
  • Figures out what kind of data it is (an email? a password? an API key?) and where it's going (a database query? a shell command? an HTTP response?)
  • Warns or blocks, depending on how risky that combination is

No LLM is involved in the analysis itself — it's fast, deterministic static analysis, so it never makes things up and never costs you tokens.

Here is everything VibeGate currently checks for:

CheckWhat it catchesResult
Command injectionUnsanitized input reaches a shell commandBlocks
SQL injectionUnsanitized input reaches a database queryBlocks
NoSQL injectionThe request body is used directly as a database filterBlocks
Template injection (SSTI)The template source itself, not just its data, comes from user inputBlocks
Insecure deserializationUntrusted data reaches an unsafe deserializer (pickle, unsafe YAML, ...)Blocks
Path traversalUnsanitized input reaches a file read, write, or deleteBlocks
XXEUntrusted XML is parsed with external entities enabledBlocks
XSSUnsanitized input is rendered as raw HTMLBlocks
Unrestricted file uploadThe uploaded file's own name is used to build the save pathBlocks
SSRFThe server fetches a URL that isn't hardcodedWarns
Open redirectA redirect target that isn't hardcodedWarns
Mass assignmentThe whole request body is passed into a model constructor or updateWarns
Sensitive data in a request bodyEmails, passwords, tokens, etc. read from the request bodyWarns
Sensitive data in a URL/queryEmails, passwords, tokens, etc. read from the query stringWarns
Sensitive data in headersEmails, passwords, tokens, etc. read from request headersWarns
File path from user inputA variable, not a hardcoded string, is used as a file pathWarns
CLI argumentsData comes from command-line argumentsWarns
Standard inputData comes from stdinWarns
Environment variablesData comes from an environment variableWarns
Unpinned GitHub ActionA workflow uses a mutable tag (@v4) instead of a commit SHAWarns
Unsafe pull_request_targetA workflow uses the pull_request_target triggerWarns
Credential loggingA password, API key, or token is passed to print/console.log/a loggerWarns
Hardcoded secretA variable named like a secret is assigned a real-looking literal valueWarns

The full, current list lives in guidance.TECHNICAL_RISKS and formatter.BLOCKING_CATEGORIES, in case this table ever drifts.

What happens when you turn it on

                    ┌───────────────────────────────┐
                    │   You ask Claude Code to      │
                    │   write or edit a file        │
                    └───────────────┬───────────────┘
                                    │
                                    ▼
                    ┌───────────────────────────────┐
                    │   Claude Code tries to save   │
                    │   the file (Write/Edit tool)  │
                    └───────────────┬───────────────┘
                                    │
                                    ▼
                    ┌───────────────────────────────┐
                    │        VibeGate hook          │
                    │   (runs automatically,        │
                    │    before the file is saved)  │
                    └───────────────┬───────────────┘
                                    │
                     scans the new code with Semgrep
                                    │
              ┌─────────────────────┼─────────────────────┐
              │                     │                     │
              ▼                     ▼                     ▼
    ┌────────────────────┐ ┌────────────────────┐ ┌──────────────────────┐
    │  No risky input    │ │   Risky input,     │ │  Risky input reaches │
    │  found             │ │   but lower risk   │ │  a critical sink     │
    │                    │ │   (e.g. shown in   │ │  (SQL/command/RCE,   │
    │                    │ │   an HTTP reply)   │ │  template injection) │
    └─────────┬──────────┘ └─────────┬──────────┘ └───────────┬──────────┘
              │                      │                        │
              ▼                      ▼                        ▼
      File is saved,         File is saved,            File is NOT saved.
      nothing shown.         plus a warning in           Claude Code sees
                              the terminal with           the block reason
                              risk + how to fix it.        and is told what
                                                            to fix.

In short: safe code passes through untouched, risky-but-survivable code gets saved with a warning attached, and code that's one step away from things like SQL injection, command injection, or remote code execution gets stopped before it ever reaches disk.

If VibeGate itself hits an unexpected error, it always lets the write through — a bug in the hook should never be the reason your work gets blocked.

Every warning and block also carries an explicit instruction telling Claude Code to mention the finding to you in its reply, not just fix it silently. That's what makes VibeGate's activity visible in the conversation, not only in a terminal log you'd have to go looking for.

What VibeGate seesWhat happens
No user input, or a language it doesn't support yetFile saves normally, nothing shown
User input found, but the risk is moderate (e.g. open redirect, mass assignment)File saves, terminal shows a warning + guidance
User input flows unsanitized into a critical sink (SQL/NoSQL query, shell command, template engine, deserializer, XML parser, file path, uploaded filename, or raw HTML output)File is not saved — Claude Code is told why

See the table in "What problem does this solve?" above for the full, per-check breakdown of what blocks vs. what only warns.

Today VibeGate understands Python, JavaScript/TypeScript, Go, Java, PHP, and Ruby, and plugs into Claude Code and Codex. More languages and tools can be added without touching the core logic.

It also checks GitHub Actions workflow files for two common CI/CD supply-chain mistakes: actions pinned to a mutable tag (@v4) instead of a commit SHA, and the unsafe pull_request_target trigger. Both warn rather than block, since they're hardening checks rather than proof of an active exploit.

See it in action

Download Tool