MCP server/ai-tools

VibeCheck MCP Server

AI-powered security audit tool for codebases.

★ 1philiphess1/vibecheck-mcp ↗by philiphess1updated
1

Add it to Claude Code

claude mcp add vibecheck -- npx -y vibecheck-audit-mcp
2

Make your agent remember this setup

vibecheck's config, env vars, and the gotchas you hit — recalled in every future Claude Code, Cursor, and Codex session.

npx conare@latest

Free · one command · indexes the sessions already on disk. Set up in the browser instead →

What it does

  • AI-powered analysis using MCP sampling with Claude
  • Real-time vulnerability definitions from MITRE CWE API
  • Automated dependency scanning via npm audit
  • Categorized security analysis including auth, API, and database rules
  • Zero configuration required to get started

Tools 2

scan_codebaseFull AI-powered security audit with real-time vulnerability data.
check_dependenciesQuick dependency-only scan using npm audit.

Try it

Scan my current project codebase for authentication and API security vulnerabilities.
Run a dependency audit on my project to check for known vulnerabilities in package-lock.json.
Perform a security audit on the src/auth.ts file and suggest remediation steps.
Check my codebase for any hardcoded secrets or environment variables that might be exposed.
Original README from philiphess1/vibecheck-mcp

VibeCheck MCP Server

AI-powered security audit tool for codebases. Analyzes code for vulnerabilities using real-time data from MITRE CWE and npm audit.

Features

  • AI-Powered Analysis: Uses MCP sampling to analyze code with Claude
  • Real-Time CWE Data: Fetches vulnerability definitions from MITRE's CWE API
  • Dependency Scanning: Uses npm audit for package vulnerability checks
  • Zero Configuration: No API keys required to get started

Installation

Claude Code (Recommended)

/plugin marketplace add philiphess1/vibecheck-mcp
/plugin install vibecheck@vibecheck

Manual Installation

Add to your Claude Desktop config (~/.claude/claude_desktop_config.json):

{
  "mcpServers": {
    "vibecheck": {
      "command": "npx",
      "args": ["-y", "vibecheck-audit-mcp"]
    }
  }
}

From Source

git clone https://github.com/philiphess1/vibecheck-mcp.git
cd vibecheck-mcp
npm install && npm run build

Tools

scan_codebase

Full AI-powered security audit with real-time vulnerability data.

Analyzes:

  • Authentication and authorization issues
  • API security vulnerabilities
  • Database security rules
  • Exposed secrets and environment variables
  • Dependency vulnerabilities (via npm audit)
  • Data flow and injection vulnerabilities

Input:

{
  "path": "/path/to/codebase",
  "categories": ["auth", "api", "secrets-env"],
  "severityThreshold": "medium"
}

Or provide files directly:

{
  "files": [
    { "path": "src/auth.ts", "content": "..." }
  ]
}

Categories:

  • auth - Authentication, sessions, middleware
  • api - API routes, endpoints
  • database-rules - Firebase/Supabase rules, Prisma schemas
  • secrets-env - Environment variables, config files
  • dependencies - package.json vulnerabilities
  • data-flow - User input handling, injection points

check_dependencies

Quick dependency-only scan using npm audit.

Input:

{
  "path": "/path/to/project",
  "includeDevDependencies": false
}

Requirements:

  • npm installed
  • package-lock.json in the project

Data Sources

Source Purpose Auth Required
MITRE CWE API Vulnerability definitions No
npm audit Package CVEs No
OWASP Security categories No (bundled)

Development

# Build
npm run build

# Watch mode
npm run dev

# Run directly
npm start

How It Works

  1. File Reading: Reads files from the specified path or accepts file contents directly
  2. Hotspot Collection: Categorizes files by security relevance (auth, api, secrets, etc.)
  3. Dependency Audit: Runs npm audit if package-lock.json exists
  4. AI Analysis: Uses MCP sampling to analyze each category with expert prompts
  5. CWE Enrichment: Fetches relevant CWE definitions from MITRE API
  6. Results: Returns structured findings with severity, CWE/OWASP refs, and remediation steps

Output Format

{
  "findings": [
    {
      "id": "uuid",
      "type": "hardcoded-secret",
      "severity": "critical",
      "title": "Hardcoded API Key",
      "description": "...",
      "filePath": "src/config.ts",
      "lineNumber": 42,
      "codeSnippet": "const API_KEY = 'sk-...'",
      "aiReasoning": "...",
      "confidence": 95,
      "cwes": [{ "id": "CWE-798", "name": "..." }],
      "owasp": [{ "id": "A02:2021", "name": "..." }],
      "remediation": {
        "summary": "Use environment variables",
        "steps": ["..."]
      }
    }
  ],
  "dependencyVulnerabilities": [...],
  "summary": {
    "totalFindings": 5,
    "critical": 1,
    "high": 2,
    "medium": 2,
    "low": 0,
    "vulnerableDependencies": 3
  },
  "scanDuration": 12500
}

License

MIT

Frequently Asked Questions

What are the key features of VibeCheck?

AI-powered analysis using MCP sampling with Claude. Real-time vulnerability definitions from MITRE CWE API. Automated dependency scanning via npm audit. Categorized security analysis including auth, API, and database rules. Zero configuration required to get started.

What can I use VibeCheck for?

Developers performing pre-commit security checks on new code modules.. Security engineers auditing legacy codebases for common injection vulnerabilities.. Teams ensuring third-party dependencies are free from known CVEs.. Automated identification of hardcoded secrets and sensitive configuration files..

How do I install VibeCheck?

Install VibeCheck by running: /plugin marketplace add philiphess1/vibecheck-mcp && /plugin install vibecheck@vibecheck

What MCP clients work with VibeCheck?

VibeCheck works with any MCP-compatible client including Claude Desktop, Claude Code, Cursor, and other editors with MCP support.

Conare · memory for coding agents

Turn this server into reusable context

Keep VibeCheck docs, env vars, and workflow notes in Conare so your agent carries them across sessions.

Set up free$npx conare@latest