VibeSec

VibeSec-Skill

A secure coding skill: the agent looks at code from a bug hunter's perspective and prevents common web vulnerabilities

Skill

Low risk

We rate an entry low when it mostly gives the agent instructions and reference material.

Why this level

  • The skill consists only of instructions and checklists and runs no code
  • The purpose is defensive: helping write secure code and review it
All reasons and checks

behisecc/vibesec-skill

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add skills/vibesec-skill

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run in a terminal in the project folder

npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a claude-code -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a cursor -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a github-copilot -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a codex -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a gemini-cli -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a cline -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a roo -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

A fork of Roo Code, same .roo folders.

Run in a terminal in the project folder

npx skills add behisecc/vibesec-skill --skill VibeSec-Skill -a opencode -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

You will need: Node.js

Checked against the repository on Sep 25, 2026, commit 0590993.

Text for your agent

Clone with git clone https://github.com/BehiSecc/VibeSec-Skill and add the folder to ~/.claude/skills globally or the project's .claude/skills. For Cursor use ~/.cursor/skills, for Codex ~/.agents/skills, for GitHub Copilot ~/.copilot/skills.

Other ways from the author
git clone https://github.com/BehiSecc/VibeSec-Skill

After cloning, add the folder to ~/.claude/skills globally or the project's .claude/skills.

This is third-party code. Review the repository files before installing.

What it does

The skill gives the agent a methodology for secure web development. A single SKILL.md walks through classes of vulnerabilities and their defenses: access control (IDOR, privilege escalation, mass assignment), client-side issues (XSS, CSRF, secret exposure, open redirects), server-side ones (SSRF, SQL injection, XXE, path traversal, insecure file upload), authentication and passwords, JWT security, and API and GraphQL concerns. Each class comes with the bypass techniques attackers use, edge cases, framework-aware and cloud-aware notes, and verification checklists. The skill activates when the agent works on a web application or when you ask for a security review or audit. Installation is a matter of copying the folder into the skills directory of Claude Code, Cursor, Codex or GitHub Copilot.

Who it is for. For developers who write or review web applications and want secure choices by default.

Good fit when

  • You are writing a web application and want to close common vulnerabilities at the code stage
  • You need a security review of a specific endpoint or data flow
  • You need a checklist for a class of vulnerabilities: XSS, SSRF, SQL injection and similar

Not a fit when

  • You need a scanner that finds vulnerabilities in a deployed application on its own
  • The task is not about the web and secure web development rules do not fit

Example request

I'm building a web app, review this code for vulnerabilities and suggest secure practices

Limitations

This is a reference methodology, not a scanner or a runtime tool; the skill does not execute code. The author states it covers common vulnerabilities, and a fuller version with broader coverage is offered separately on the vibesec.sh site. The material is in English.

How to disable. Remove the copied skill folder from ~/.claude/skills or the project's .claude/skills, and from the skills directory of other agents.

Security check

  • The skill consists only of instructions and checklists and runs no code
  • The purpose is defensive: helping write secure code and review it

README in short

The README presents VibeSec as a skill that helps the agent write secure code and avoid shipping common vulnerabilities to production. Installation is described for Claude Code, Cursor, Codex, GitHub Copilot and Antigravity by cloning the repository and adding the folder to the skills directory. A coverage table lists vulnerability classes: access control, client-side and server-side issues, authentication and API security. It highlights bypass techniques, edge cases, framework and cloud awareness, and checklists. The README notes the skill covers common vulnerabilities and that a fuller version is available on vibesec.sh; it is Apache-2.0 licensed.

SKILL.md

---
name: VibeSec-Skill
description: This skill helps Claude write secure web applications. Use this when working on any web application or when a user requests a scan or audit to ensure security best practices are followed.
---

# Secure Coding Guide for Web Applications

## Overview

This guide provides comprehensive secure coding practices for web applications. As an AI assistant, your role is to approach code from a **bug hunter's perspective** and make applications **as secure as possible** without breaking functionality.

**Key Principles:**
- Defense in depth: Never rely on a single security control
- Fail securely: When something fails, fail closed (deny access)
- Least privilege: Grant minimum permissions necessary
- Input validation: Never trust user input, validate everything server-side
- Output encoding: Encode data appropriately for the context it's rendered in

## Access Control Issues

Access control vulnerabilities occur when users can access resources or perform actions beyond their intended permissions.

### Core Requirements

For every data point and action that requires authentication: each user must only access their own data, use non-guessable identifiers instead of sequential IDs, and revoke access tokens and sessions when an account is removed or deleted.

FAQ

Does the skill scan the application itself?

No. It is methodology and checklists the agent uses to write and review code. There is no tool execution or scanning in the skill.

Does it cover every vulnerability?

The author says common vulnerability classes are covered, and an extended version is offered separately on vibesec.sh.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIVibeSec

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.