←Leaderboard/Security/vbsec
Last commit on September 28, 2026·Created on May 13, 2026

tanviet12/vbsec

“A security auditor for AI-generated code and staged files.”
Combined rank
#658
across all skills
In Security
#24
category rank
Stars
286
+7.9% in last 7d
Forks
136
+14.3% in last 7d
Watchers
0
0 watchers in last 7d
Traction scoreGitHub stars can be faked, so popularity alone can be misleading. Traction Score looks for broader signs of recent attention, adoption, and active maintenance.
TL;DR

vbsec identifies common security vulnerabilities in AI-generated code, specifically targeting the 21 most frequent flaws found in vibe coding. It provides application security engineers with bilingual reports and the ability to perform pre-commit audits on staged files.

The tool integrates live CVE lookups via OSV.dev and supports an agentic patch-and-verify loop to automatically fix detected issues.

WHO IT'S FOR
Application security engineers
scanning AI-generated code for common vulnerabilities
Full-stack developers
performing pre-commit security audits on staged files
DevSecOps engineers
integrating live CVE lookups into AI workflows
Technical leads
reviewing security of pull requests via AI agents
Repository contents

1 skill file

Categories
Compatible AgentsThe repository documents support for these agents. The skills may also work with other agents that can load SKILL.md files, but they may need some setup or small changes.

Use this skill

Follow the documented setup, then try a first task.

I’m using

Automatic installation for detected agents

Installs: Installs the vbsec skill for each supported tool detected by the installer. · Claude Code, OpenAI Codex CLI, Google Antigravity

Before you start
  • Git
  • At least one of Claude Code, OpenAI Codex CLI, or Google Antigravity
  1. In a terminal, clone the repository into `~/vbsec`, then run its installer. The installer detects which supported tools are present and installs the skill for each one.

    git clone https://github.com/tanviet12/vbsec ~/vbsec
    ~/vbsec/scripts/install.sh
skills/antigravity/vbs-scan-security/SKILL.md ↗ · Checked Oct 2, 2026README.md ↗ · Checked Oct 2, 2026

Give it something to do.

Suggested first task

Run a default whole-repository security scan

Uses vbs-scan-security

  • A code repository or source-code folder opened as the current Google Antigravity workspace
Use the vbs-scan-security skill to scan this workspace for security vulnerabilities and report in English. Use the default whole-repository scope, leave --sca and --auto-fix disabled, and save the generated report under vbsec-reports/ as documented.
skills/antigravity/vbs-scan-security/SKILL.md ↗ · Checked Oct 2, 2026README.md ↗ · Checked Oct 2, 2026