SkillAgentSearch skills...

vbsec

Security scanning skill for Claude Code, Codex and Antigravity. Finds the 21 most common vulnerabilities in AI-written code and shows how to fix each one.

Install / Use

npx skills add tanviet12/vbsec

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

90/100

Category

Security

Supported Platforms

Claude Code
OpenAI Codex

Our assessment of vbsec

vbsec scores 90/100 on our quality scale, 438th of 1,000 Security skills we index (top 44%).

Its SKILL.md is 13 KB long, well organised into 16 sections with 6 code examples: a thorough specification that gives an agent plenty to work with.

It has 286 GitHub stars, a meaningful sign that others use it.

Substance
30/30
Structure
20/20
Description
15/15
Adoption
10/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 3 days ago, so vbsec is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-10-01. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

vbsec compared with similar skills

All 4 of these similar skills score higher than vbsec; compare them before choosing.

SkillScoreStarsUpdatedFormat
vbsec (this skill)by tanviet12902863d agoSKILL.md
algorithmic-artby anthropics100177.9k9d agoSKILL.md
pptxby anthropics100177.9k9d agoSKILL.md
designby nextlevelbuilder100130.2k10d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k10d agoSKILL.md

Frequently asked questions

How do I install vbsec?
Run npx skills add tanviet12/vbsec. The install tabs above show the steps for each supported agent.
Which AI agents does vbsec work with?
It is written for Claude Code and OpenAI Codex, as a SKILL.md file. Other agents that read the same format can often use it too.
Is vbsec safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is vbsec still maintained?
The repository was last updated 3 days ago, so vbsec is actively maintained.
<h1 align="center">vbsec — Security scanning for AI-written code</h1> <p align="center">A security scanning skill for Claude Code, Codex and Antigravity: it reads your code, finds the 21 most common vulnerability types, and shows you how to fix each one.<br>Free · Open source · Nothing extra to install</p> <p align="center"> <a href="./LICENSE"><img src="https://img.shields.io/badge/license-MIT-blue" alt="MIT license"></a> <a href="https://github.com/tanviet12/vbsec/stargazers"><img src="https://img.shields.io/github/stars/tanviet12/vbsec?style=flat&color=2ea44f" alt="GitHub stars"></a> <img src="https://img.shields.io/badge/Claude%20Code-%E2%9C%93-d97757" alt="Claude Code"> <img src="https://img.shields.io/badge/OpenAI%20Codex-%E2%9C%93-black" alt="OpenAI Codex"> <img src="https://img.shields.io/badge/Google%20Antigravity-%E2%9C%93-4285f4" alt="Google Antigravity"> </p> <p align="center"> <b><a href="#install">Install</a></b> · <b><a href="docs/examples/sample-report.md">Sample report</a></b> · <b><a href="#what-vbsec-catches">21 vulnerability types</a></b> · <b><a href="README.vi.md">🇻🇳 Tiếng Việt</a></b> </p> <p align="center"> <a href="docs/examples/sample-report.md"><img src="docs/images/sample-report.png" alt="vbsec report: verdict FAIL, table of 6 critical issues" width="760"></a><br> <sub>A real report from scanning a sample Express + React app. Click the image to read the full report.</sub> </p>

What vbsec does

  • Finds vulnerabilities in AI-written code: passwords in source, SQL injection, broken access control, JWTs accepted without signature checks, wide-open CORS and more: 21 of the most common types
  • Explains them for people who aren't security experts: every issue says why it's dangerous, how an attacker would exploit it step by step, the current code, and the fixed code
  • Understands code instead of matching strings: it traces data from user input to the dangerous call, so it raises far fewer false alarms than pattern-based scanners
  • Goes deep on 5 languages: Go, PHP, TypeScript/JavaScript, Python, .NET/C#, including popular frameworks such as Express, NestJS, Next.js, React, Django, FastAPI, Laravel and ASP.NET Core
  • Scans exactly what you need: the whole repo, uncommitted changes only, one commit, one pull request, or the last N days of commits
  • Works without git: drop AI-generated code into a folder and scan it right away
  • Stays fast on big repos: splits the work across several agents running in parallel, then merges the results
  • Reports in English or Vietnamese, saved as a file in vbsec-reports/ you can hand to whoever fixes it, with a JSON summary at the end for CI/CD

Example: what vbsec catches

The code below works. Clicking through the app by hand, you'd never notice a problem. AI assistants write code like this all the time.

// src/lib/auth.ts
const payload = jwt.decode(token);      // decodes only, does NOT verify the signature
(req as any).user = payload;

// src/routes/search.ts
const rows = await sequelize.query(
  `SELECT id, name, price FROM products WHERE name LIKE '%${q}%'`   // q comes from the URL
);

vbsec reports 2 CRITICAL issues:

| Issue | Impact | Fix vbsec suggests | |---|---|---| | JWT-NONE-ALGORITHM | Anyone can mint their own role: "admin" token without the secret key | Use jwt.verify(token, secret, { algorithms: ["HS256"] }) | | SQL-INJECTION | Typing ' UNION SELECT email, password_hash... into the search box dumps the whole user table | Pass parameters with replacements: { q: `%${q}%` } instead of building the string |

Read the full sample report to see how vbsec explains each issue.

Test results

The repo ships 8 sample apps with known, planted bugs (Go, PHP, TypeScript, Python, .NET), including hard cases: data flowing through several files, sanitizers written wrong, race conditions when deducting a balance. Each set also has traps that look like bugs but are safe, to measure false alarms.

| | Latest run | |---|---| | Bugs caught | 54/55 | | False alarms on safe traps | 0 |

AI output can vary between runs. Re-run it yourself with ./scripts/run-fixtures.sh (see tests/README.md). vbsec has also been tried on OWASP Juice Shop and caught the vulnerability classes matching its documented challenges.

How vbsec works

It reads code like a reviewer, not like grep. Many scanners flag every query( as "possible SQL injection", so they cry wolf constantly and people stop reading. vbsec reads the surrounding code, works out where the data comes from, and only then decides.

Take the same line of code:

db.query(`SELECT * FROM products WHERE name = '${x}'`)
  • If x comes from a search box the user types into (req.query.q): flagged, because anyone can type malicious SQL there.
  • If x is a constant in the code or a value from a config file: not flagged, because outsiders can't change it.

To tell these apart, vbsec sorts data into 4 trust levels, from "sent by a stranger" (forms, URLs, headers, uploads) to "produced by the system" (constants, environment variables). Only stranger-supplied data that reaches a dangerous call without being cleaned gets reported.

It knows each language and framework. On top of the general rules, vbsec has dedicated rules for Go, PHP, TypeScript/JavaScript, Python and .NET, so it knows each library's traps. For example: Prisma.sql is safe but $queryRawUnsafe is not, bypassSecurityTrustHtml in Angular switches off XSS protection, and Gin's debug mode left on in production.

Small repos scan instantly, big ones get split up. Under about 20 code files, vbsec scans directly in roughly 30–60 seconds. Larger repos are split into parts for up to 3 agents working in parallel, then the results are merged and de-duplicated.

One issue per line item. A line of code with 2 problems (say, reading another user's data and a race condition) shows up as 2 separate issues. Counts stay honest, and each one can be ticked off as it's fixed.

Reports in English or Vietnamese. Vietnamese is the default; add lang=en for English. The report ends with a fixed-format JSON block in English, so CI/CD can read it and block merges while critical issues remain.

The same rules on all three tools. Claude Code, Codex and Antigravity share one rule set and produce the same findings. The only difference: Claude Code runs in parallel, so it's faster on large repos.

Install

You need one of: Claude Code, OpenAI Codex CLI, Google Antigravity.

git clone https://github.com/tanviet12/vbsec ~/vbsec
~/vbsec/scripts/install.sh

The script detects which of these tools you have and installs the skill for each. To update later: cd ~/vbsec && git pull.

Manual install, installing for one specific tool, troubleshooting: docs/en/installation.md.

Usage

| Tool | How to run | |---|---| | Claude Code | /vbs-scan-security | | OpenAI Codex CLI | $vbs-scan-security | | Google Antigravity | say "scan security for this repo" |

/vbs-scan-security lang=en                       # scan the whole folder (default), English report
/vbs-scan-security uncommitted lang=en           # uncommitted changes only; worth running before every commit
/vbs-scan-security pr id 42 lang=en              # scan pull request #42
/vbs-scan-security commit within 7days lang=en   # commits from the last 7 days

Reports are saved to vbsec-reports/scan-<timestamp>.md inside the scanned folder. Add vbsec-reports/ to .gitignore; vbsec reminds you if it's missing.

All options: docs/en/usage.md.

What vbsec catches

| Category | Issues | |---|---| | Leaked secrets, config | HARDCODED-SECRET · VERBOSE-ERROR-DEBUG-MODE · CORS-MISCONFIG | | Injection | SQL-INJECTION · COMMAND-INJECTION · XSS · INSECURE-DESERIALIZATION · SSRF · PATH-TRAVERSAL | | Authentication, authorization | BROKEN-ACCESS-CONTROL · IDOR · MASS-ASSIGNMENT · JWT-NONE-ALGORITHM · WEAK-PASSWORD-HASHING · CSRF | | Abuse protection | BRUTE-FORCE · MISSING-RATE-LIMIT · RACE-CONDITION · UNRESTRICTED-FILE-UPLOAD | | Dependencies | OUTDATED-DEPENDENCY · SLOPSQUATTING (package names the AI made up, registered first by attackers) |

Severity, vulnerable and safe code examples, and which languages have dedicated rules: docs/en/rules.md.

Limitations

vbsec is a first line of defense, not proof that your system is secure.

  • It does not replace a security review by professionals
  • It does not guarantee catching 100% of vulnerabilities
  • It does not query CVE databases online. Check dependencies for known vulnerabilities with npm audit, pip-audit, govulncheck, composer audit

Add a badge to your repo

Scanned with vbsec and fixed everything? Add this badge to your README:

vbsec: security scanned · passed

[![vbsec: security scanned · passed](https://img.shields.io/badge/vbsec-security%20scanned%20%C2%B7%20passed-2ea44f?logo=data%3Aimage%2Fsvg%2Bxml%3Bbase64%2CPHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjZmZmIiBzdHJva2Utd2lkdGg9IjIuMiIgc3Ryb2tlLWxpbmVjYXA9InJvdW5kIiBzdHJva2UtbGluZWpvaW49InJvdW5kIj48cGF0aCBkPSJNMjAgMTNjMCA1LTMuNSA3LjUtNy42NiA4Ljk1YTEgMSAwIDAgMS0uNjctLjAxQzcuNSAyMC41IDQgMTggNCAxM1Y2YTEgMSAwIDAgMSAxLTFjMiAwIDQuNS0xLjIgNi4yNC0yLjcyYTEuMTcgMS4xNyAwIDAgMSAxLjUyIDBDMTQuNTEgMy44MSAxNyA1IDE5IDVhMSAxIDAgMCAxIDEgMXoiLz48cGF0aCBkPSJtOSAxMiAyIDIgNC00Ii8%2BPC9zdmc%2BCg%3D%3D)](https://github.com/tanviet12/vbsec)

Sponsors

vbsec is free and open source thanks to:

<table> <tr> <td align="center" valign="top" width="50%"> <a href="https://sepay.vn?utm_source=github&utm_medium=readme&utm_campaign=vbsec"><img src="docs/images/sponsor-sepay.svg" alt="SePay" height="42"></a><br> <b><a href="https://sepay.vn?utm_source=github&utm_medium=readme&utm_campaign=vbsec">SePay</a></b><br> Open Banking platform: automatic bank transfer confirmation and API connections to Vietnamese banks </td> <td align="center" valign="top" width="50%"> <a href="https://123host.vn?utm_source=github&utm_medium=readme&utm_campaign=vbsec"><img src="docs/images/sponsor-123host.svg" alt="123HOST" height="42"></a><br> <b><a href="https://123host.vn?utm_source=github&utm_medium=readme&utm_campaign=vbsec">123HOST</a></b><br> Hosting, VPS, servers and domains for businesses and developers in Vietnam </td> </tr> </table>

Authors

vbsec distills security experience from running real payment and hosting systems, which get attacked every day, into a rule set that lets AI review the code AI writes.

Other open-source projects:

  • Sano — turn Word documents into audiobooks with AI; Vietnamese voices that run on your own machin

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars286
CategorySecurity
Updated3d ago
Forks136

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions