BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

VibeSec Security Skill

Skill Security Usable
Works inClaude Code
Usable Reviewed

Security co-pilot that teaches Claude to approach code from a bug hunter's perspective.

Security skill that coaches Claude (and Cursor, Codex, Copilot) to review and write code from a bug hunter's perspective, built from 5+ years of bug bounty experience. Covers IDOR, XSS, CSRF, SSRF, SQL injection, XXE, path traversal, JWT/session handling, and GraphQL security, with framework-aware patterns and specific bypass-technique checklists. The author states it covers roughly 60-70% of common vulnerabilities; a more complete version lives at vibesec.sh.

1,194 starsApache-2.0 (commercial OK)FreeQuick setup
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Security co-pilot that teaches Claude to approach code from a bug hunter's perspective. Catches XSS, injection, auth bypasses, and other vulnerabilities before they ship.

Development teams who want continuous security review during coding, not just at the end of a sprint.

Claude Code Claude Cowork Claude Chat

https://github.com/BehiSecc/VibeSec-Skill

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
git clone https://github.com/BehiSecc/VibeSec-Skill ~/.claude/skills/VibeSec-Skill   # or clone into .claude/skills in your project for project-only use

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

After installing, paste this into Claude:

Help me catch security vulnerabilities during coding, not after deployment
CostFree

Trust Signals Reviewed

Stars1,194Contributors3Last updated2026-02-17LicenseApache-2.0 (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-17 · scanner v1

Community Pulse Active

Discussed on Hacker News, Reddit

1 mentions across 1 sources

Reviewer notes

Reviewed review. These are observations, not a security certification.

Security-focused. Coaches Claude to think like a bug hunter. Good complement to Trail of Bits.

Community tool. Source reviewed.

Things to check

  • Skill effectiveness depends on clear code context and prompt framing; it catches common patterns but is not a substitute for dedicated SAST tools or professional penetration testing. Integration requires Claude conversation setup rather than automated CI/CD pipeline deployment.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
3/5
Security
4/5
Overall score3.15 / 5.00 UsableEvaluatedApr 2026
Security-focused. Coaches Claude to think like a bug hunter. Good complement to Trail of Bits.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →