{"_id":"@all-safe-projects/allsafe-vibeguard","_rev":"5-b3af39b61c572e3ac49946cc3185a83f","name":"@all-safe-projects/allsafe-vibeguard","dist-tags":{"alpha":"0.2.0-alpha.1","latest":"0.2.1"},"versions":{"0.1.0":{"name":"@all-safe-projects/allsafe-vibeguard","version":"0.1.0","keywords":["security","vibe-coding","cli","sast","ai-code","vulnerability-scanner","appsec"],"author":{"name":"All Safe Areas"},"license":"UNLICENSED","_id":"@all-safe-projects/allsafe-vibeguard@0.1.0","maintainers":[{"name":"allsafevendor","email":"npm@employee.allsafeprojects.org"}],"homepage":"https://projects.allsafeareas.org/en-US/sensors-russia/npm-allsafe-vibecode","bugs":{"url":"https://allsafeareas.org/security/vulnerability-disclosure"},"bin":{"allsafe-vibe":"dist/cli.js"},"dist":{"shasum":"f8c512923605dba97782940ad5b414e4bb239c81","tarball":"https://registry.npmjs.org/@all-safe-projects/allsafe-vibeguard/-/allsafe-vibeguard-0.1.0.tgz","fileCount":21,"integrity":"sha512-9g5f0KjYaaOTb1webNIIZFZPkGtspUlawVvXoKQXfpf1cQ7jhXo1RWV8KtdWpAECukXBzxKz+MyghyAX+d25mA==","signatures":[{"sig":"MEYCIQDY5ym40LAreEJifX5VqkLTqPhclL1VE5b9iCdSHBmUMgIhAMFIrRp0758x6111TBEEEVNkWoqEaESfwVKTryCxk/dP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":35741},"main":"./dist/index.js","type":"module","_from":"file:/tmp/vibeguard-final-audit/archive/all-safe-projects-allsafe-vibeguard-0.1.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"funding":"https://sponsor.allsafeareas.org/","scripts":{"scan":"npm run build && node dist/cli.js scan","test":"vitest run","build":"npm run clean && tsc -p tsconfig.json && node scripts/make-executable.mjs","check":"npm run build && npm test","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","prepack":"npm run check","test:watch":"vitest","prepublishOnly":"npm run security:release","security:release":"bash scripts/prepublish-security-audit.sh"},"_npmUser":{"name":"allsafevendor","email":"npm@employee.allsafeprojects.org"},"_resolved":"/tmp/vibeguard-final-audit/archive/all-safe-projects-allsafe-vibeguard-0.1.0.tgz","_integrity":"sha512-9g5f0KjYaaOTb1webNIIZFZPkGtspUlawVvXoKQXfpf1cQ7jhXo1RWV8KtdWpAECukXBzxKz+MyghyAX+d25mA==","_npmVersion":"10.8.2","description":"Local security deployment gate for AI-generated JavaScript and TypeScript applications","directories":{},"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/allsafe-vibeguard_0.1.0_1785019432756_0.7915369558584864","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@all-safe-projects/allsafe-vibeguard","version":"0.1.1","keywords":["security","vibe-coding","cli","sast","ai-code","vulnerability-scanner","appsec"],"author":{"name":"All Safe Areas"},"license":"UNLICENSED","_id":"@all-safe-projects/allsafe-vibeguard@0.1.1","maintainers":[{"name":"allsafevendor","email":"npm@employee.allsafeprojects.org"}],"homepage":"https://projects.allsafeareas.org/en-US/sensors-russia/npm-allsafe-vibecode","bugs":{"url":"https://allsafeareas.org/security/vulnerability-disclosure"},"bin":{"allsafe-vibe":"dist/cli.js"},"dist":{"shasum":"9b80f4001d6a601aa18bb679a114915073fa9f62","tarball":"https://registry.npmjs.org/@all-safe-projects/allsafe-vibeguard/-/allsafe-vibeguard-0.1.1.tgz","fileCount":21,"integrity":"sha512-xEbkumRo0OvPn+9w7+I5rpa3UrqKCb+d7mDjvLITH8pCXko43MA9sRMVw72iQxN6k8fCE18zjytyuZDEH5U17w==","signatures":[{"sig":"MEQCIDQyIAYzZYGiuoeGmbtOlfuc04GWLxWj0h7FBnWN3VJZAiBq94QdMYv+X99KbzYOrZxbafUVQfCqmV0SzLkzK3OdVw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":38250},"main":"./dist/index.js","type":"module","_from":"file:/tmp/vibeguard-0.1.1-release/all-safe-projects-allsafe-vibeguard-0.1.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"funding":"https://sponsor.allsafeareas.org/","scripts":{"scan":"npm run build && node dist/cli.js scan","test":"vitest run","build":"npm run clean && tsc -p tsconfig.json && node scripts/make-executable.mjs","check":"npm run build && npm test","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","prepack":"npm run check","test:watch":"vitest","prepublishOnly":"npm run security:release","security:release":"bash scripts/prepublish-security-audit.sh"},"_npmUser":{"name":"allsafevendor","email":"npm@employee.allsafeprojects.org"},"_resolved":"/tmp/vibeguard-0.1.1-release/all-safe-projects-allsafe-vibeguard-0.1.1.tgz","_integrity":"sha512-xEbkumRo0OvPn+9w7+I5rpa3UrqKCb+d7mDjvLITH8pCXko43MA9sRMVw72iQxN6k8fCE18zjytyuZDEH5U17w==","_npmVersion":"10.8.2","description":"Local security deployment gate for AI-generated JavaScript and TypeScript applications","directories":{},"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/allsafe-vibeguard_0.1.1_1785020171752_0.9264725774659959","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-alpha.1":{"name":"@all-safe-projects/allsafe-vibeguard","version":"0.2.0-alpha.1","keywords":["security","vibe-coding","cli","sast","ai-code","vulnerability-scanner","appsec"],"author":{"name":"All Safe Areas"},"license":"UNLICENSED","_id":"@all-safe-projects/allsafe-vibeguard@0.2.0-alpha.1","maintainers":[{"name":"allsafevendor","email":"npm@employee.allsafeprojects.org"}],"homepage":"https://projects.allsafeareas.org/en-US/sensors-russia/npm-allsafe-vibecode","bugs":{"url":"https://allsafeareas.org/security/vulnerability-disclosure"},"bin":{"allsafe-vibe":"dist/cli.js"},"dist":{"shasum":"3423690bde871f93f6cc18af94e7ff78e55aaf25","tarball":"https://registry.npmjs.org/@all-safe-projects/allsafe-vibeguard/-/allsafe-vibeguard-0.2.0-alpha.1.tgz","fileCount":25,"integrity":"sha512-H9zWIOUtAja/LdC3WoZTbyUW5Trpsj0uqZ+FBdofkdPhPuv2Lp/cX6sUCa1mSjG2DNq0Wh7Tscj756AGLqydAw==","signatures":[{"sig":"MEUCIQC9pC6lL6oipTE5oVtYpucNciUcs5ooVWFsqbez0PcedAIgGMTiABVnrusVE2CiWHkD2u/QhB3vTglbzO3bVi1Mlyw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":67005},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"funding":"https://sponsor.allsafeareas.org/","gitHead":"cd96714f6d829b2d7f620568aeb2e48266670d2a","scripts":{"scan":"npm run build && node dist/cli.js scan","test":"vitest run","build":"npm run clean && tsc -p tsconfig.json && node scripts/make-executable.mjs","check":"npm run build && npm test","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","prepack":"npm run check","test:watch":"vitest","prepublishOnly":"npm run security:release","security:release":"bash scripts/prepublish-security-audit.sh"},"_npmUser":{"name":"allsafevendor","email":"npm@employee.allsafeprojects.org"},"_npmVersion":"10.8.2","description":"Local semantic security deployment gate for AI-generated JavaScript and TypeScript applications","directories":{},"_nodeVersion":"20.20.2","dependencies":{"@babel/parser":"^7.29.7"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/allsafe-vibeguard_0.2.0-alpha.1_1785115398565_0.32562211120760653","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@all-safe-projects/allsafe-vibeguard","version":"0.2.0","keywords":["security","vibe-coding","cli","sast","ai-code","vulnerability-scanner","appsec"],"author":{"name":"All Safe Areas"},"license":"UNLICENSED","_id":"@all-safe-projects/allsafe-vibeguard@0.2.0","maintainers":[{"name":"allsafevendor","email":"npm@employee.allsafeprojects.org"}],"homepage":"https://projects.allsafeareas.org/en-US/sensors-russia/npm-allsafe-vibecode","bugs":{"url":"https://allsafeareas.org/security/vulnerability-disclosure"},"bin":{"allsafe-vibe":"dist/cli.js"},"dist":{"shasum":"b8d8c08de7fac197055bdba1804c611202a67287","tarball":"https://registry.npmjs.org/@all-safe-projects/allsafe-vibeguard/-/allsafe-vibeguard-0.2.0.tgz","fileCount":25,"integrity":"sha512-EetwwnUzeFO/SVsUBgN0udaW7rhFpzp1G/q/KYNWMkOKm7bY+jK7iXd3RjElrEGt0S+3kZfUBdQW7E07yl/iOw==","signatures":[{"sig":"MEUCIDhLP1Jz8iBsp9SSb4za2oEhbh+TAVE/KC+didODMH0oAiEAwUGjpckhFGBIQdzhDLgaZMHIS8YC4mfe1zi+MowxN/0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":66997},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"funding":"https://sponsor.allsafeareas.org/","gitHead":"cd96714f6d829b2d7f620568aeb2e48266670d2a","scripts":{"scan":"npm run build && node dist/cli.js scan","test":"vitest run","build":"npm run clean && tsc -p tsconfig.json && node scripts/make-executable.mjs","check":"npm run build && npm test","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","prepack":"npm run check","test:watch":"vitest","prepublishOnly":"npm run security:release","security:release":"bash scripts/prepublish-security-audit.sh"},"_npmUser":{"name":"allsafevendor","email":"npm@employee.allsafeprojects.org"},"_npmVersion":"10.8.2","description":"Local semantic security deployment gate for AI-generated JavaScript and TypeScript applications","directories":{},"_nodeVersion":"20.20.2","dependencies":{"@babel/parser":"^7.29.7"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/allsafe-vibeguard_0.2.0_1785115608001_0.2860787451303275","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@all-safe-projects/allsafe-vibeguard","version":"0.2.1","description":"Local AST and data-flow security scanner for AI-generated JavaScript and TypeScript applications","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"bin":{"allsafe-vibe":"dist/cli.js"},"scripts":{"clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","build":"npm run clean && tsc -p tsconfig.json && node scripts/make-executable.mjs","test":"vitest run","test:watch":"vitest","check":"npm run build && npm test","scan":"npm run build && node dist/cli.js scan","security:release":"bash scripts/prepublish-security-audit.sh","prepack":"npm run check","prepublishOnly":"npm run security:release"},"engines":{"node":">=20"},"keywords":["security","vibe-coding","cli","sast","ai-code","vulnerability-scanner","appsec"],"author":{"name":"All Safe Areas"},"license":"UNLICENSED","homepage":"https://projects.allsafeareas.org/en-US/sensors-russia/npm-allsafe-vibecode","bugs":{"url":"https://allsafeareas.org/security/vulnerability-disclosure"},"funding":"https://sponsor.allsafeareas.org/","dependencies":{"@babel/parser":"^7.29.7"},"devDependencies":{"@types/node":"^26.1.1","typescript":"^7.0.2","vitest":"^4.1.10"},"publishConfig":{"access":"public"},"_id":"@all-safe-projects/allsafe-vibeguard@0.2.1","gitHead":"cd96714f6d829b2d7f620568aeb2e48266670d2a","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-RFrGQsXLvU7TqfDqDH8vKaJ83k2mXGXOxao3BEqydwTnGG2bhU7OnQwhRWJrJjwZH6w586EaNhi6CP1ERjquEw==","shasum":"0fb7fd1cc6c6409bb90eacf3ae6f5d0f43940acd","tarball":"https://registry.npmjs.org/@all-safe-projects/allsafe-vibeguard/-/allsafe-vibeguard-0.2.1.tgz","fileCount":25,"unpackedSize":67958,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDl2v4WZyyjZKnobkKHYvrUfhDLWNKMJBCpRnH7pLTMgwIgM9m6DLmcm670V0iKHh99l/AFubkk7vis5s01LSU9rdw="}]},"_npmUser":{"name":"allsafevendor","email":"npm@employee.allsafeprojects.org"},"directories":{},"maintainers":[{"name":"allsafevendor","email":"npm@employee.allsafeprojects.org"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/allsafe-vibeguard_0.2.1_1785116013496_0.5263471085444584"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-25T22:43:52.577Z","modified":"2026-07-27T01:33:33.844Z","0.1.0":"2026-07-25T22:43:52.916Z","0.1.1":"2026-07-25T22:56:11.919Z","0.2.0-alpha.1":"2026-07-27T01:23:18.732Z","0.2.0":"2026-07-27T01:26:48.150Z","0.2.1":"2026-07-27T01:33:33.678Z"},"bugs":{"url":"https://allsafeareas.org/security/vulnerability-disclosure"},"author":{"name":"All Safe Areas"},"license":"UNLICENSED","homepage":"https://projects.allsafeareas.org/en-US/sensors-russia/npm-allsafe-vibecode","keywords":["security","vibe-coding","cli","sast","ai-code","vulnerability-scanner","appsec"],"description":"Local AST and data-flow security scanner for AI-generated JavaScript and TypeScript applications","maintainers":[{"name":"allsafevendor","email":"npm@employee.allsafeprojects.org"}],"readme":"# AllSafe VibeGuard\n\nAllSafe VibeGuard is a local semantic security deployment gate for JavaScript and TypeScript projects generated or modified with AI tools. It combines focused secret detection, AST inspection, and scope-aware data-flow analysis to report high-risk implementation mistakes before deployment.\n\nThe scanner runs locally, does not upload source code, and is designed to fit into developer workstations and CI release checks. VibeGuard detects risky outcomes commonly found in quickly generated code; it does not attempt to determine whether a human or an AI authored the code.\n\n## What's new in 0.2.0\n\n- AST analysis for JavaScript, TypeScript, JSX, and TSX through Babel\n- Scope-aware taint tracking from request input through variables to dangerous sinks\n- Compact source-to-propagation-to-sink traces for data-flow findings\n- Detection of fail-open handlers and placeholder authorization checks\n- Detection of incomplete JWT validation, unsafe session cookies, and credentialed wildcard CORS\n- Detection of predictable security values created with `Math.random()`\n- Detection of unfinished security `TODO` and `FIXME` controls\n- Focused checks for SSRF, SQL injection, command injection, path traversal, and dynamic execution\n- Reduced false positives for unrelated functions, CSRF cookies, and ordinary UI randomness\n\nVersion `0.2.0` is the first stable release of the semantic analysis engine. It remains a focused deployment gate rather than a replacement for code review, dependency auditing, penetration testing, or a complete SAST platform.\n\n## Quick start\n\nNode.js 20 or newer is required.\n\n```bash\nnpx @all-safe-projects/allsafe-vibeguard scan .\n```\n\nThe scanner reads the selected local directory. It does not upload project source code.\n\n## CLI\n\n```text\nallsafe-vibe scan [path] [options]\nallsafe-vibe [path] [options]\n\nOptions:\n  --json                  Print JSON\n  --fail-on <severity>    critical, high, medium, low, none\n  --no-color              Disable terminal colors\n  --max-files <count>     Override the 10,000-file safety limit\n  --max-total-mb <mb>     Override the 25 MB content safety limit\n  --timeout <seconds>     Override the 30-second safety limit\n  -h, --help              Show help\n  -v, --version           Show version\n```\n\nExamples:\n\n```bash\nnpx @all-safe-projects/allsafe-vibeguard scan . --fail-on medium\nnpx @all-safe-projects/allsafe-vibeguard scan ./services/api --json\nnpx @all-safe-projects/allsafe-vibeguard scan . --max-files 50000 --max-total-mb 150 --timeout 120\n```\n\nThe default failure threshold is `high`. Exit code `0` means the configured threshold was not reached, `1` means it was reached, and `2` means the scan could not complete.\n\n## Current checks\n\n- Embedded private keys and credentials shaped like AWS, GitHub, or Stripe secrets\n- Hardcoded passwords, tokens, API keys, and sensitive `.env` files\n- Predictable security-secret fallbacks and JWT decoding without signature verification in the same control scope\n- Incomplete JWT trust checks and authentication cookies missing defensive attributes\n- Unconditional authorization stubs, unfinished security controls, and fail-open exception paths\n- Predictable randomness used for tokens, sessions, reset codes, or similar security values\n- Credentialed wildcard CORS configurations\n- Request data flowing through local variables into SSRF, command execution, SQL, filesystem, or dynamic-code sinks\n- Disabled TLS certificate verification and other focused dangerous-code patterns\n\nEach finding includes severity, confidence, analysis engine, evidence with common credentials redacted, impact, and a remediation suggestion. Data-flow findings also contain a compact source-to-sink trace.\n\nExample trace:\n\n```text\nsource       server.ts:8   Untrusted HTTP input: req.query.url\npropagation  server.ts:9   Value propagated through destination\nsink         server.ts:10  Dangerous operation: fetch\n```\n\n## Why VibeGuard\n\nDependency auditors answer whether installed packages have published vulnerabilities. Secret scanners answer whether credentials look committed. VibeGuard instead focuses on security controls that appear complete but are unsafe in implementation: verification without pinned trust claims, placeholder authorization, fail-open handling, predictable security values, and request data reaching dangerous APIs.\n\nThe scanner runs locally and does not upload source code. AST parsing is used for JavaScript, TypeScript, JSX, and TSX; text patterns remain available for configuration and secret-bearing files.\n\n## Verdicts\n\n| Verdict | Meaning |\n| --- | --- |\n| `PASS` | No findings were detected by the current rule set. |\n| `REVIEW` | One or more low or medium findings require review. |\n| `BLOCK` | One or more high or critical findings were detected. |\n\n## Programmatic API\n\n```js\nimport { scanProject } from \"@all-safe-projects/allsafe-vibeguard\";\n\nconst result = await scanProject(\".\");\nconsole.log(result.verdict, result.findings);\n```\n\nOptional resource limits can be overridden for controlled environments:\n\n```js\nconst result = await scanProject(\".\", {\n  limits: {\n    maxFiles: 5_000,\n    timeoutMs: 15_000\n  }\n});\n```\n\nDefault limits protect the scanner from unexpectedly large or hostile directory trees: 10,000 files, 5,000 directories, depth 30, 25 MB total scanned content, 1 MB per file, 1,000 findings, and 30 seconds. Exceeding a limit stops the scan with exit code `2`; it does not silently return an incomplete result.\n\n## Limitations\n\nThe data-flow engine is scope-aware but intentionally lightweight. It does not yet provide complete inter-file or framework-aware reachability analysis. VibeGuard can produce false positives and false negatives, and a `PASS` result is not proof that an application is secure. Review findings in context and use layered security testing before production deployment.\n\n## Security reports\n\nReport vulnerabilities through the [All Safe Areas vulnerability disclosure page](https://allsafeareas.org/security/vulnerability-disclosure).\n\n## License\n\nThis package is proprietary and distributed as `UNLICENSED`. Limited internal-use rights and restrictions are stated in [LICENSE](./LICENSE).\n","readmeFilename":"README.md"}