Traction scoreGitHub stars can be faked, so popularity alone can be misleading. Traction Score looks for broader signs of recent attention, adoption, and active maintenance.
vbsec identifies common security vulnerabilities in AI-generated code, specifically targeting the 21 most frequent flaws found in vibe coding. It provides application security engineers with bilingual reports and the ability to perform pre-commit audits on staged files.
The tool integrates live CVE lookups via OSV.dev and supports an agentic patch-and-verify loop to automatically fix detected issues.
WHO IT'S FOR
Application security engineers
scanning AI-generated code for common vulnerabilities
Full-stack developers
performing pre-commit security audits on staged files
Compatible AgentsThe repository documents support for these agents. The skills may also work with other agents that can load SKILL.md files, but they may need some setup or small changes.
Follow the documented setup, then try a first task.
I’m using
Automatic installation for detected agents
Installs: Installs the vbsec skill for each supported tool detected by the installer. · Claude Code, OpenAI Codex CLI, Google Antigravity
Before you start
Git
At least one of Claude Code, OpenAI Codex CLI, or Google Antigravity
In a terminal, clone the repository into `~/vbsec`, then run its installer. The installer detects which supported tools are present and installs the skill for each one.
Installs: Installs vbs-scan-security globally for every Claude Code workspace through `~/.claude/skills/`. · Claude Code
Before you start
Claude Code CLI or desktop
Git
A Git repository to scan
GitHub `gh` CLI only when using the `pr id <n>` scope
Platform: macOS or Linux; on Windows use WSL2 because native Windows is not officially supported
In a terminal outside Claude Code, clone the repository into `~/vbsec` and create the global skill symlink. If you change the clone destination, adjust the source path in the second command accordingly.
Restart Claude Code so it discovers the newly installed skill.
After restarting, enter `/vbs-scan-security` inside a Claude Code session to verify the installation. A scan report with the documented header indicates success.
A code repository or source-code folder opened as the current Google Antigravity workspace
Use the vbs-scan-security skill to scan this workspace for security vulnerabilities and report in English. Use the default whole-repository scope, leave --sca and --auto-fix disabled, and save the generated report under vbsec-reports/ as documented.