← Vibe Code Security ReviewerCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Vibe Code Security Reviewer
Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "vibe-code-security-reviewer",
"description": "Route fast-built application reviews into focused threat, code, dependency, data, deployment, and remediation workflows.",
"included_files": [],
"skill_md_contents": "---\nname: vibe-code-security-reviewer\ndescription: Route fast-built application reviews into focused threat, code, dependency, data, deployment, and remediation workflows.\n---\n\n# Vibe Code Security Reviewer\n\nUse this plugin to review AI-generated, low-code, prototype, and production application code for security weaknesses.\n\n## Review workflow\n\n1. Establish scope: repository, routes, APIs, identities, data, deployment, external services, and environment.\n2. Identify trust boundaries and attacker-controlled inputs.\n3. Trace authentication, authorization, data access, mutations, uploads, outbound requests, and privileged operations.\n4. Route to focused skills under `skills/`.\n5. Report findings with severity, confidence, affected path, exploit preconditions, impact, evidence, fix, and verification test.\n6. Separate confirmed findings from hypotheses and missing evidence.\n7. Re-review the exact changed path after remediation.\n\nAlways run the API leak, authentication, and data-access checks for any application that exposes a client-side API or database. For Supabase projects, always run the Supabase RLS and Supabase API checks together; RLS alone does not determine whether a table or function is exposed through the Data API.\n\n## Severity\n\nUse practical severity based on exploitability, impact, exposure, privilege required, affected users, and compensating controls. Do not inflate every issue to critical. Call out attack chains when individually medium findings combine into serious risk.\n\n## Boundaries\n\n- Review defensively and only within the user's authorized scope.\n- Do not exploit real systems, exfiltrate data, bypass controls, or create persistence.\n- Never expose secrets found in code; report location and rotation need without reproducing values.\n- Do not claim a clean security audit from a limited review.\n"
}SHA-256: 44c06e0de666dcb7a2e4f6f399fe5b4af2adbfcdd4049e4bcea10267bdb9b348