AI-generated code created through rapid prototyping often conceals critical defects: hardcoded API keys, hallucinated phantom packages, lazy swallowed exceptions, and stealthy network telemetry in compiled binaries. Vibe Audit provides a 360° audit suite combining deep static AST source diagnostics and real-time Windows runtime socket inspection.
Instantly toggle between static repository AST analysis and dynamic runtime network packet capture for Windows executables (.exe).
Vibe-coded projects differ from conventional legacy codebases. Our AST ruleset understands LLM code patterns to pinpoint real vulnerabilities.
Detects API keys and secrets (OpenAI, Anthropic, GitHub PAT, RSA/SSH private keys, AWS). Leverages Shannon entropy algorithms to discard repetitive strings and contextually ignores unit test mocks and placeholders.
LLMs often invent imaginary library names or omit dependencies from manifests. Vibe Audit cross-checks AST import statements against lockfiles, requirements.txt, and package.json.
Scans for raw SQL query concatenations and arbitrary code execution (eval(), child_process.exec(), os.system()). Accurately distinguishes legitimate JavaScript string calls like RegExp.prototype.exec().
Pinpoints silent exception blocks swallowing critical errors (except: pass, catch(e){}). Applies progressive architectural thresholds restricted exclusively to application source code.
Static code audits cannot catch behavior in compiled, packaged applications (Tauri, Electron, PyInstaller). Vibe Audit spawns the executable under observation and inspects its live sockets and network emissions.
msedgewebview2.exe, ffmpeg.exe) and their I/O telemetry.
Every package recommended by generative AI is audited against the universal open-source vulnerability database to defuse CVEs before production.
Automated batch scans of Python (requirements.txt) and Node.js (package.json) dependencies against the OSV API.
Operates seamlessly even on air-gapped security workstations thanks to a bundled offline database of common critical CVEs.
Export comprehensive reports in ready-to-share Markdown for GitHub pull requests or structured JSON for automated CI/CD security gates.
Lightweight installation on Python 3.10+ on Windows 10/11.
git clone https://github.com/gotenash/vibe-audit.git cd "vibe audit" pip install psutil requests
python app.py # Open browser at http://localhost:5173
python vibe_audit.py ./my-project # Instant terminal audit report