VibeSec
VibeSec-Skill
A secure coding skill: the agent looks at code from a bug hunter's perspective and prevents common web vulnerabilities
Low risk
We rate an entry low when it mostly gives the agent instructions and reference material.
Why this level
- The skill consists only of instructions and checklists and runs no code
- The purpose is defensive: helping write secure code and review it
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add skills/vibesec-skillDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run in a terminal in the project folder
npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a claude-code -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a cursor -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a github-copilot -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a codex -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a gemini-cli -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a cline -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a roo -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
A fork of Roo Code, same .roo folders.
Run in a terminal in the project folder
npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a opencode -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Clone with git clone https://github.com/BehiSecc/VibeSec-Skill and add the folder to ~/.claude/skills globally or the project's .claude/skills. For Cursor use ~/.cursor/skills, for Codex ~/.agents/skills, for GitHub Copilot ~/.copilot/skills.
Other ways from the author
git clone https://github.com/BehiSecc/VibeSec-SkillAfter cloning, add the folder to ~/.claude/skills globally or the project's .claude/skills.
This is third-party code. Review the repository files before installing.
What it does
The skill gives the agent a methodology for secure web development. A single SKILL.md walks through classes of vulnerabilities and their defenses: access control (IDOR, privilege escalation, mass assignment), client-side issues (XSS, CSRF, secret exposure, open redirects), server-side ones (SSRF, SQL injection, XXE, path traversal, insecure file upload), authentication and passwords, JWT security, and API and GraphQL concerns. Each class comes with the bypass techniques attackers use, edge cases, framework-aware and cloud-aware notes, and verification checklists. The skill activates when the agent works on a web application or when you ask for a security review or audit. Installation is a matter of copying the folder into the skills directory of Claude Code, Cursor, Codex or GitHub Copilot.
Who it is for. For developers who write or review web applications and want secure choices by default.
Good fit when
- You are writing a web application and want to close common vulnerabilities at the code stage
- You need a security review of a specific endpoint or data flow
- You need a checklist for a class of vulnerabilities: XSS, SSRF, SQL injection and similar
Not a fit when
- You need a scanner that finds vulnerabilities in a deployed application on its own
- The task is not about the web and secure web development rules do not fit
Example request
I'm building a web app, review this code for vulnerabilities and suggest secure practicesLimitations
This is a reference methodology, not a scanner or a runtime tool; the skill does not execute code. The author states it covers common vulnerabilities, and a fuller version with broader coverage is offered separately on the vibesec.sh site. The material is in English.
How to disable. Remove the copied skill folder from ~/.claude/skills or the project's .claude/skills, and from the skills directory of other agents.
Security check
- The skill consists only of instructions and checklists and runs no code
- The purpose is defensive: helping write secure code and review it
README in short
The README presents VibeSec as a skill that helps the agent write secure code and avoid shipping common vulnerabilities to production. Installation is described for Claude Code, Cursor, Codex, GitHub Copilot and Antigravity by cloning the repository and adding the folder to the skills directory. A coverage table lists vulnerability classes: access control, client-side and server-side issues, authentication and API security. It highlights bypass techniques, edge cases, framework and cloud awareness, and checklists. The README notes the skill covers common vulnerabilities and that a fuller version is available on vibesec.sh; it is Apache-2.0 licensed.
SKILL.md
--- name: VibeSec-Skill description: This skill helps Claude write secure web applications. Use this when working on any web application or when a user requests a scan or audit to ensure security best practices are followed. --- # Secure Coding Guide for Web Applications ## Overview This guide provides comprehensive secure coding practices for web applications. As an AI assistant, your role is to approach code from a **bug hunter's perspective** and make applications **as secure as possible** without breaking functionality. **Key Principles:** - Defense in depth: Never rely on a single security control - Fail securely: When something fails, fail closed (deny access) - Least privilege: Grant minimum permissions necessary - Input validation: Never trust user input, validate everything server-side - Output encoding: Encode data appropriately for the context it's rendered in ## Access Control Issues Access control vulnerabilities occur when users can access resources or perform actions beyond their intended permissions. ### Core Requirements For every data point and action that requires authentication: each user must only access their own data, use non-guessable identifiers instead of sequential IDs, and revoke access tokens and sessions when an account is removed or deleted.
FAQ
Does the skill scan the application itself?
No. It is methodology and checklists the agent uses to write and review code. There is no tool execution or scanning in the skill.
Does it cover every vulnerability?
The author says common vulnerability classes are covered, and an extended version is offered separately on vibesec.sh.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents