
VibeSec-Skill
This skill helps Claude write secure code and prevent common vulnerabilities.

This skill helps Claude write secure code and prevent common vulnerabilities.

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…


Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

KQL Injection in adx-mcp-server via table_name parameter — CVSS 8.8

Tool to search secrets in various filetypes.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

A simple file-based scanner to look for potential AWS access and secret keys in files

SAST CLI for scanning Java, JavaScript, and .NET applications plus AWS Lambda functions, detecting code vulnerabilities and over-permissive IAM…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Cloud native secrets management for developers - never leave your command line for secrets.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Snyk CLI scans and monitors your projects for security vulnerabilities.

Prevents you from committing secrets and credentials into git repositories

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…