{"_id":"@arisrhiannon/vibecheck","_rev":"2-fb940ec75e176164b84979b61f8cb955","name":"@arisrhiannon/vibecheck","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@arisrhiannon/vibecheck","version":"0.1.0","keywords":["vibe-coding","security","sast","taint-analysis","ast","babel","secrets","owasp","ai-generated-code","agent","mcp","llms-txt","ci","ship-gate","typescript"],"author":{"name":"Aris Rhiannon"},"license":"MIT","_id":"@arisrhiannon/vibecheck@0.1.0","maintainers":[{"name":"arisrhiannon","email":"12osemberg.arias@gmail.com"}],"homepage":"https://github.com/ArisRhiannon/vibecheck#readme","bugs":{"url":"https://github.com/ArisRhiannon/vibecheck/issues"},"bin":{"vibecheck":"dist/cli.js"},"dist":{"shasum":"1c51f954fc6f8f9b0bde2fd202d574e26ce206c1","tarball":"https://registry.npmjs.org/@arisrhiannon/vibecheck/-/vibecheck-0.1.0.tgz","fileCount":10,"integrity":"sha512-Izn8HY4Y0fHlmfrv/cpmK/QiUKmtsJUHUqS1/QnsRDC0ns0SxxdiTi5vbRQXOZk5T3J1M7M4sKWn3OUw3uqX4A==","signatures":[{"sig":"MEUCIQCqtHCaOZF44ORerVOi8hdFlVy1kU9LkNvJ5ABt9UBIOQIgYq19djNBlSRboyiJefBXc78xVdh/k9f1Rd+6J2hYjB4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3203315},"main":"dist/index.js","type":"module","module":"dist/index.js","engines":{"bun":">=1.1.0","node":">=20"},"exports":{".":"./dist/index.js"},"gitHead":"da23c5f6f696dcb82ece73025e74929a1b2c8b25","scripts":{"test":"bun test","build":"bun run scripts/build.ts","check":"bun run typecheck && bun test","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"arisrhiannon","email":"12osemberg.arias@gmail.com"},"repository":{"url":"git+https://github.com/ArisRhiannon/vibecheck.git","type":"git"},"_npmVersion":"11.11.0","description":"Agent-native 'safe to ship?' gate for vibe-coded apps: real parsers (Babel JS/TS + Python ast + Go go/parser) with inter-procedural (return-taint + cross-file) taint for the AI-failure classes (secrets, SQLi via raw APIs, XSS, SSRF, path traversal, comman","directories":{},"_nodeVersion":"24.14.1","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.1.0","typescript":"^5.6.0","@types/node":"^22.0.0","@babel/types":"^7.29.7","@babel/parser":"^7.29.7","@babel/traverse":"^7.29.7","@types/babel__traverse":"^7.28.0"},"_npmOperationalInternal":{"tmp":"tmp/vibecheck_0.1.0_1780247536766_0.48301664597589977","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@arisrhiannon/vibecheck","version":"0.2.0","description":"Agent-native 'safe to ship?' gate for vibe-coded apps: real parsers (Babel JS/TS + Python ast + Go go/parser) with inter-procedural (return-taint + cross-file) taint for the AI-failure classes (secrets, SQLi via raw APIs, XSS, SSRF, path traversal, comman","type":"module","license":"MIT","author":{"name":"Aris Rhiannon"},"homepage":"https://github.com/ArisRhiannon/vibecheck#readme","repository":{"type":"git","url":"git+https://github.com/ArisRhiannon/vibecheck.git"},"bugs":{"url":"https://github.com/ArisRhiannon/vibecheck/issues"},"keywords":["vibe-coding","security","sast","taint-analysis","ast","babel","secrets","owasp","ai-generated-code","agent","mcp","llms-txt","ci","ship-gate","typescript"],"main":"dist/index.js","module":"dist/index.js","exports":{".":"./dist/index.js"},"bin":{"vibecheck":"dist/cli.js"},"scripts":{"test":"bun test","typecheck":"tsc --noEmit","build":"bun run scripts/build.ts","prepublishOnly":"bun run build","check":"bun run typecheck && bun test"},"engines":{"bun":">=1.1.0","node":">=20"},"dependencies":{},"devDependencies":{"@babel/parser":"^7.29.7","@babel/traverse":"^7.29.7","@babel/types":"^7.29.7","@types/babel__traverse":"^7.28.0","@types/bun":"^1.1.0","@types/node":"^22.0.0","typescript":"^5.6.0"},"_id":"@arisrhiannon/vibecheck@0.2.0","gitHead":"92ad98f981bf824b46a8e1b7e147fed7077328fb","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-FB4kaFg2ClFuzFPDIQncH3hicssb0gpHutR/giNR2Hnyvg+diwO3/MZ+XVEK68R3wykBKm7xlUAiDuJEcbKC7A==","shasum":"65754aa0fcdb72e5e0d45dc9eb5e57833bd3c488","tarball":"https://registry.npmjs.org/@arisrhiannon/vibecheck/-/vibecheck-0.2.0.tgz","fileCount":10,"unpackedSize":3204773,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arisrhiannon%2fvibecheck@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDtVEZ9gP0chRynS1TzvQU8OKAZJbil+rfUdcXAyTW7jAIhANh4RS+PNu3L4Q/d4NoRmSqSxfHHYyY+itH3rcnqcfsE"}]},"_npmUser":{"name":"arisrhiannon","email":"12osemberg.arias@gmail.com"},"directories":{},"maintainers":[{"name":"arisrhiannon","email":"12osemberg.arias@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/vibecheck_0.2.0_1780302277314_0.9717452950046264"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-31T17:12:16.567Z","modified":"2026-06-01T08:24:37.829Z","0.1.0":"2026-05-31T17:12:16.938Z","0.2.0":"2026-06-01T08:24:37.561Z"},"bugs":{"url":"https://github.com/ArisRhiannon/vibecheck/issues"},"author":{"name":"Aris Rhiannon"},"license":"MIT","homepage":"https://github.com/ArisRhiannon/vibecheck#readme","keywords":["vibe-coding","security","sast","taint-analysis","ast","babel","secrets","owasp","ai-generated-code","agent","mcp","llms-txt","ci","ship-gate","typescript"],"repository":{"type":"git","url":"git+https://github.com/ArisRhiannon/vibecheck.git"},"description":"Agent-native 'safe to ship?' gate for vibe-coded apps: real parsers (Babel JS/TS + Python ast + Go go/parser) with inter-procedural (return-taint + cross-file) taint for the AI-failure classes (secrets, SQLi via raw APIs, XSS, SSRF, path traversal, comman","maintainers":[{"name":"arisrhiannon","email":"12osemberg.arias@gmail.com"}],"readme":"# vibecheck\n\n[![ci](https://github.com/ArisRhiannon/vibecheck/actions/workflows/ci.yml/badge.svg)](https://github.com/ArisRhiannon/vibecheck/actions/workflows/ci.yml)\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)\n\nA fast, **agent-native** \"safe to ship?\" gate for vibe-coded apps. It parses your **JS/TS/JSX/TSX**\n(`@babel/parser`), **Python** (the stdlib `ast`), and **Go** (`go/parser`) with **real parsers** and uses **taint analysis**\n(inter-procedural for JS/TS, Python, and Go — return-taint + param→sink summaries, within a file and across files) to flag the security classes AI coding agents get wrong — committed secrets, SQL\ninjection through *abstracted* raw-query APIs, XSS, SSRF, path traversal, command injection, insecure\ndeserialization, weak JWT/CORS/cookies — and ranks every finding by **confidence** so an agent can fix\nthe real ones and ignore the noise.\n\n```sh\nvibecheck .          # human report (severity + confidence)\nvibecheck . --ci     # exit 1 only on high-confidence (taint-backed) issues\nvibecheck . --json   # machine-readable findings for agents / CI\n```\n\n## What it is — and what it is not (read this)\n\nvibecheck is **not** a replacement for [Semgrep](https://semgrep.dev) or\n[CodeQL](https://codeql.github.com). Those are deeper, broader, multi-language engines and you should\nrun them for full coverage. vibecheck aims to be **better on one narrow, measurable axis**: a\n**low-false-positive, taint-backed gate for the AI-vibe-coding failure classes that runs inside agent\nloops and pre-commit in milliseconds**, with **published precision/recall** so you can trust the\n`--ci`/MCP signal. Use it *alongside* the big engines, not instead of them.\n\n| | vibecheck | Semgrep | CodeQL |\n|--|--|--|--|\n| Parsing | real AST (Babel JS/TS/JSX + Python `ast`) | real, many langs | real, many langs |\n| Data-flow | inter-procedural (return-taint + param→sink; intra-file + cross-file by import) | taint (Pro) | full inter-procedural |\n| Languages | **JS/TS/JSX/TSX + Python + Go** | many | many |\n| Speed / infra | ms, local, no account | fast | slower, CI-oriented |\n| Agent-native (MCP, confidence gating) | **yes, first-class** | partial | no |\n| Breadth of rules | small, focused | 2000+ | huge |\n\nIf you only adopt one general SAST, adopt Semgrep or CodeQL. Adopt vibecheck as the **fast agent/CI\npre-flight** that won't drown an agent in false positives.\n\n## Measured quality (not claimed)\n\nAgainst a labeled benchmark of **91 cases** across JS/TS, Python **and** Go (vulnerable + safe + deliberately\ntricky-safe), the core detectors score (see [`METRICS.md`](METRICS.md), reproduce with `bun benchmark/run.ts`):\n\n- **Precision 100%**, **Recall 100%**, **F1 100%** on the corpus.\n\nThe tricky-safe cases that produce **zero false positives** include: parameterized queries, tagged-\ntemplate SQL, numeric-coerced and schema-validated input, ORM/RegExp `.exec()`, Supabase **anon** /\nStripe **publishable** keys, hardened cookies, allow-listed CORS, and pinned JWT algorithms — exactly\nthe patterns a regex linter trips on. This benchmark is curated; for a **real-world** measurement (9 pinned\nOSS repos, 1,218 files, manually triaged), see [`docs/CORPUS.md`](docs/CORPUS.md) — which exposed a\ncritical bug (Python/Go files weren't being scanned in real scans) and drove precision fixes (relative\nredirects, server-source-only SSRF).\n\n## Confidence \n\nEvery finding has a **confidence**:\n- `high` — a user-input **source provably flows into the sink** (taint-backed), or a deterministic fact\n  (committed secret, JWT `none`). These fail `--ci` and are what the MCP `scan` tool returns by default.\n- `medium` — a dangerous sink on a non-literal value with no proven source (e.g. `eval(x)`).\n- `review` — a structural smell that needs a human (e.g. a route with no visible auth). **Excluded from\n  `--ci` and from the agent loop by default**, so agents never chase phantom work. Add `--all` to include them.\n\n## Install & use\n\n```sh\nnpm i -D @arisrhiannon/vibecheck    # or: bun add -d @arisrhiannon/vibecheck (Node >= 20)\nvibecheck . --ci\nvibecheck explain VC-SQLI\nvibecheck mcp           # MCP stdio server exposing a `scan` tool (high-confidence by default)\n```\n\nAgents: see [`AGENTS.md`](AGENTS.md) — run `vibecheck . --ci` before declaring a task done and fix every\nhigh-confidence finding.\n\n> JS/TS scanning needs nothing extra. **Python** scanning requires **`python3` on PATH**; **Go** scanning\n> requires a **`go` toolchain on PATH** (the analyzer is compiled once and cached). If a runtime is absent\n> those files are skipped; if an analyzer **fails**, a warning is printed to **stderr** (so a crash never\n> silently drops findings).\n\n## Rules (implemented + benchmarked)\n\nTaint-backed: `VC-RCE-EVAL`, `VC-RCE-CHILD-PROCESS`, `VC-SQLI`, `VC-XSS-REACT`, `VC-XSS-DOM`, `VC-SSRF`,\n`VC-PATH-TRAVERSAL`, `VC-OPEN-REDIRECT`. AST config: `VC-CORS-WILDCARD`, `VC-JWT-NONE`,\n`VC-JWT-UNPINNED`, `VC-COOKIE-INSECURE`, `VC-STACK-EXPOSURE`. Provenance/secrets: `VC-SECRET-*` (8),\n`VC-ENV-COMMITTED/DRIFT/MISSING`, `VC-NEXT-PUBLIC-SECRET`, `VC-SUPABASE-SERVICE-ROLE`. Advisory:\n`VC-ROUTE-NO-AUTH` (review), `VC-INPUT-NO-VALIDATION`. **Python** (`VC-PY-*`): `VC-PY-RCE`,\n`VC-PY-CMDI`, `VC-PY-SQLI`, `VC-PY-DESERIALIZE`, `VC-PY-YAML`, `VC-PY-SSTI`, `VC-PY-OPEN-REDIRECT`,\n`VC-PY-PATH`. **Go** (`VC-GO-*`): `VC-GO-CMDI`, `VC-GO-SQLI`, `VC-GO-PATH`, `VC-GO-OPEN-REDIRECT`,\n`VC-GO-SSRF`. `vibecheck explain <id>` prints the fix for each.\n\n## Limitations\n\n- **JS/TS/JSX/TSX + Python + Go** (Python needs `python3`, Go needs a `go` toolchain on PATH). More\n  languages are roadmap (each via its own real parser, never hand-rolled).\n- **Taint scope:** JS/TS taint is **inter-procedural with real cross-file module resolution** — function\n  summaries carry **return-taint** and **parameter→sink** reachability, resolved within a file and **across\n  files via resolved relative imports** (named, **aliased** `a as b`, and **namespace** `* as ns`),\n  propagated **multi-hop** by a fixpoint; sanitizers respected. Not tracked (false negatives): re-exports\n  (`export { x } from …`), default exports, CommonJS `require`/dynamic `import()`, bare/package imports,\n  chains deeper than ~7 hops in worst-case file order, methods, and destructured params. **Python** is also\n  inter-procedural (return-taint + param→sink **and class `@staticmethod` resolution**, intra-file and cross-file via resolved `from .mod import`/\n  `import mod`; not resolved: `import a.b` dotted-unaliased, `*`/re-exports, decorators). Python request\n  **sources** span Flask, Django, **aiohttp** (`request.match_info`, `await request.post()`), FastAPI/\n  Starlette (`request.query_params`/`path_params`, `await request.json()/form()`), Tornado, Bottle, Pyramid. **Go** is\n  inter-procedural **within and across packages** (return-taint + param→sink; unaliased `pkg.Func`\n  resolves by package name). Aliased package imports (`import u \"…/util\"`) and multi-return assignments\n  (`x, _ := f(src)`) are not tracked.\n- Config/secret rules are pattern-based where AST adds no value.\n- A high-signal gate and early-warning — **not a proof of security**. Pair it with Semgrep/CodeQL and review.\n\n## Config — `.vibecheck.json`\n\n```json\n{ \"ignoreRules\": [\"VC-INPUT-NO-VALIDATION\"], \"allowPaths\": [\"test/**\"], \"failSeverity\": \"high\" }\n```\n\n## License\n\nMIT © 2026 Aris Rhiannon — see [LICENSE](LICENSE).\n","readmeFilename":"README.md"}