Logo Vibe Audit Vibe Audit
← Home
Logo Vibe Audit
Python 3.10+ • AST & Heuristics Windows (.EXE) Real-Time Socket Inspector OSV.dev CVE & LLM Hallucination Scanner Open Source (MIT)

Security & Integrity Audit for Vibe Coding

AI-generated code created through rapid prototyping often conceals critical defects: hardcoded API keys, hallucinated phantom packages, lazy swallowed exceptions, and stealthy network telemetry in compiled binaries. Vibe Audit provides a 360° audit suite combining deep static AST source diagnostics and real-time Windows runtime socket inspection.

View on GitHub Explore Dashboard
⚡ Real-Time Cyberpunk Glassmorphism Web App

Interactive Dual-Tab Web Dashboard

Instantly toggle between static repository AST analysis and dynamic runtime network packet capture for Windows executables (.exe).

Vibe Audit Dashboard
0 to 100
Multi-dimensional Readiness Score
AST & Entropy
Elimination of false alarms
Socket Radar
Millisecond TCP/UDP tracking
OSV.dev + ASN
CVEs & organization mapping
Static Code Analysis Engine

Precise Diagnostics & Zero False Positives

Vibe-coded projects differ from conventional legacy codebases. Our AST ruleset understands LLM code patterns to pinpoint real vulnerabilities.

🔑

Secrets Scanner & Shannon Entropy

Detects API keys and secrets (OpenAI, Anthropic, GitHub PAT, RSA/SSH private keys, AWS). Leverages Shannon entropy algorithms to discard repetitive strings and contextually ignores unit test mocks and placeholders.

✦ Contextual mock & fixture suppression
👻

Phantom Packages & Hallucinations

LLMs often invent imaginary library names or omit dependencies from manifests. Vibe Audit cross-checks AST import statements against lockfiles, requirements.txt, and package.json.

✦ Flags Dependency Confusion & Typosquat risks
🛡️

Injection Vulnerabilities & Dynamic Code

Scans for raw SQL query concatenations and arbitrary code execution (eval(), child_process.exec(), os.system()). Accurately distinguishes legitimate JavaScript string calls like RegExp.prototype.exec().

✦ Granular AST discrimination without RegExp false alarms
🏗️

"God Files" Monoliths & Lazy Exceptions

Pinpoints silent exception blocks swallowing critical errors (except: pass, catch(e){}). Applies progressive architectural thresholds restricted exclusively to application source code.

✦ Tiered thresholds: Mild (400) / Med (800) / Critical (>1500)
📡 Runtime Behavioral Inspection (.EXE)

Socket Flow Radar & Process Tree Visualizer

Static code audits cannot catch behavior in compiled, packaged applications (Tauri, Electron, PyInstaller). Vibe Audit spawns the executable under observation and inspects its live sockets and network emissions.

  • ✓ Recursive Process Tree: Tracks sub-processes (msedgewebview2.exe, ffmpeg.exe) and their I/O telemetry.
  • ✓ Reverse DNS & ASN Intelligence: Resolves server owners in real time (Microsoft, Cloudflare, OpenAI, Amazon AWS...).
  • ✓ Stealth Telemetry Detection: Instantly flags hidden analytics beacons smuggled within 3rd-party dependencies.
🟢
100% OFFLINE
Zero external packets
🟡
TELEMETRY
Recognized trackers
🔴
UNVERIFIED TRAFFIC
Unknown endpoints
NETWORK EVENT TIMELINE Real-Time
[14:02:11] TCP CONNECT 104.18.32.7:443 Cloudflare CDN
[14:02:12] HTTPS GET /v1/chat/completions OpenAI API
[14:02:15] POST /events/telemetry Sentry Ingest
Vulnerability Intelligence

Live & Offline OSV.dev Integration

Every package recommended by generative AI is audited against the universal open-source vulnerability database to defuse CVEs before production.

Batch OSV Queries

Automated batch scans of Python (requirements.txt) and Node.js (package.json) dependencies against the OSV API.

Offline Signature Index

Operates seamlessly even on air-gapped security workstations thanks to a bundled offline database of common critical CVEs.

1-Click Exportable Reports

Export comprehensive reports in ready-to-share Markdown for GitHub pull requests or structured JSON for automated CI/CD security gates.

Installation & Quick Start

Lightweight installation on Python 3.10+ on Windows 10/11.

View on GitHub
1. Clone repository and install dependencies:
git clone https://github.com/gotenash/vibe-audit.git
cd "vibe audit"
pip install psutil requests
Option A: Web Dashboard UI (Recommended)
python app.py
# Open browser at http://localhost:5173
Option B: Command Line Interface (CLI)
python vibe_audit.py ./my-project
# Instant terminal audit report