โœจ Featured: Dependency Hallucination: The Silent Security Risk in AI-Generated Code

Does your code have
soul?

We detect fake npm packages, exposed secrets, and bloated slop that Cursor & Claude Code leave behind. Get your copy-paste fix-prompts in seconds.

AI App Launch Readiness Audit โ€ข From $10.00

3 Simple Steps to Audit Your Codebase

Deterministic AST scans, OWASP security verification, and Cursor refactor prompts in under 10 seconds.

01

1. Input Repository or ZIP

Paste your public GitHub repo URL, sign in to link private repositories in 1 click, or upload a local project .zip archive.

02

2. Secure Checkout

Pay $10 for a single audit or subscribe to Pro Builder Pass ($39/mo) via encrypted Stripe Checkout.

03

3. Instant Report & Fixes

Receive evidence-backed security findings, technical debt metrics, copy-paste fix prompts, and launch your app safely.

How The Launch Readiness Audit Engine Works

Deterministic AST static analysis combined with multi-layer AI synthesis evaluates your codebase safely before customer launch.

The 4 Audit Assurance Pillars

๐Ÿ›ก๏ธ

1. SAST Security Audit

Scans for OWASP ASVS 4.0 flaws, hardcoded credentials, unsanitized SQL/command sinks, and dangerous dynamic code execution.

๐Ÿ“ฆ

2. Supply Chain & CVEs

Inspects package dependencies, unpinned wildcard versions, license compliance, and known package vulnerabilities.

๐Ÿงฉ

3. Code Quality & Debt

Measures cognitive complexity debt, swallowed exceptions, unhandled promise rejections, and strict type safety.

๐Ÿค–

4. AI Code Vibe Score

Evaluates AI authoring ratio, over-commenting density, structural boilerplate, and non-existent SDK method hallucinations.

๐Ÿ“„ Verified Report Format

Explore an Interactive Sample Report

See how evidence-backed security findings, code quality debt metrics, and copy-paste prompts for Cursor & Windsurf look in a completed report.

View Interactive Sample Report โ†’
โšก

Under 10-Second Scans

Fast AST analysis and findings delivered in seconds.

๐Ÿ”’

No Untrusted Execution

We never run customer package scripts, build commands, or binaries.

๐ŸŽฏ

Safe Coding-Agent Prompts

Every finding includes copy-paste prompts for Cursor, Windsurf, Replit, Claude Code & Codex.

Built for the New Era of Coding

Traditional scanners are for legacy code. Vibe Code Detector is the only tool built to understand the specific patterns and pitfalls of agentic AI coding in Cursor, Windsurf, v0, and Claude Code.

Cursor IDE & Claude
โšก
01 โ€ข HALLUCINATIONS & SECRETS

Catch Fake Packages & Exposed Keys

  • โœ“Catch hallucinated npm packages before supply-chain hijacking
  • โœ“Prevent exposed Stripe & OpenAI secret keys in client bundles
  • โœ“Flag swallowed promise rejections that freeze app loading
Windsurf & Agentic IDEs
๐ŸŒŠ
02 โ€ข TOKEN & LOOP PROTECTION

Stop $500 LLM Token Loops

  • โœ“Detect infinite retry loops that drain $500+ in LLM tokens
  • โœ“Prune bloated try-catch boilerplate and zombie tutorial comments
  • โœ“Clean up generic variable naming entropy (data / temp)
v0 & Bolt Scaffolds
๐Ÿš€
03 โ€ข ONE-CLICK PROMPT DECK

Copy-Paste Fix Prompts

  • โœ“Ready-to-use refactor prompts formatted for Cursor & Claude Code
  • โœ“Ordered by fix priority for instant one-click refactoring
  • โœ“1 Free Rescan within 14 days to verify all fix prompts pass

Frequently Asked Questions

Everything you need to know about Vibe Code Detector

An evidence-backed security and code quality review designed specifically for apps built with AI tools like Cursor, Windsurf, Replit Agent, v0, Claude Code, and Codex. It identifies OWASP security vulnerabilities, exposed secrets, cognitive complexity debt, and package CVEs before you launch.
When you submit a public GitHub repo, private link with PAT, or local .zip archive, our engine runs deterministic AST static analysis rules combined with multi-layer AI synthesis to evaluate code quality, security vulnerabilities, and package debt before customer launch.
We enforce a strict Zero Secret Exposure policy. API keys and credentials are automatically redacted server-side. Customer code is never executed (no package scripts or binaries are run) and is never stored or used to train AI models.
Every paid audit includes 1 rescan within 7 days. After applying our copy-paste coding-agent prompts in Cursor, Windsurf, or Replit to fix findings, request a rescan to verify your fixes pass before going live.
You can submit a GitHub Private Repository URL with a Personal Access Token (PAT), or upload a local .zip archive directly from your machine.
We offer simple transparent pricing: $0 for instant code snippet pre-scans, $10 for a full repository Launch Audit (one-time, includes 1 free rescan), and $39/month for Pro Builder Pass for active builders and teams.