待翻譯:Show HN: VibeGuard – security linter for AI-generated code
AI 服務暫時不可用,以下為來源摘要,待恢復後補全翻譯:Notifications You must be signed in to change notification settings Fork 0 Star 1 BranchesTags Open more actions menu Latest commit History 2 Commits 2 Commits Folders and files NameName Last commit message Last commit…
AI 服務暫時不可用,以下為來源正文,待恢復後補全翻譯。
Notifications You must be signed in to change notification settings Fork 0 Star 1 BranchesTags Open more actions menu Latest commit History 2 Commits 2 Commits Folders and files NameName Last commit message Last commit date tests tests vibeguard vibeguard README.md README.md attesta-report.json attesta-report.json requirements.txt requirements.txt Repository files navigation The security linter built for AI-generated code. The Problem AI coding assistants — GitHub Copilot, Cursor, Claude, ChatGPT — write code fast. Really fast. Faster than any security review can keep up with. The problem is they also confidently produce the same security mistakes over and over. Not because they are bad tools. Because they were trained on millions of code examples — and millions of those examples had security vulnerabilities in them. The exact mistakes AI coding assistants make repeatedly: SQL queries built with string concatenation instead of parameterized queries Secrets and API keys hardcoded directly into source files User input passed to eval(), exec(), subprocess.shell=True without validation JWT tokens verified without checking the algorithm — the alg:none bypass XML parsers configured to allow external entities — XXE vulnerabilities Insecure random number generation used for security-sensitive values Path traversal — user-controlled file paths with no sanitization CORS configured to accept any origin Debug mode left enabled in production configuration Pickle deserialization of untrusted data — remote code execution Traditional linters like Bandit and Semgrep catch some of these. But they use generic rules that were not built around the specific patterns AI tools produce. VibeGuard is different — every rule was written by studying actual AI-generated code and cataloguing the exact vulnerability patterns these tools produce. Demo $ vibeguard scan --path ./my-ai-generated-project [*] VibeGuard v1.0.0 — AI-Generated Code Security Linter [*] Scanning: ./my-ai-generated-project [*] Running 47 AI-pattern rules... app/database.py:34 CRITICAL SQL_INJECTION f-string used in SQL query — classic Copilot pattern app/auth.py:12 CRITICAL HARDCODED_SECRET API key assigned to variable — detected by entropy app/utils.py:89 HIGH COMMAND_INJECTION subprocess called with shell=True + user input app/api.py:156 HIGH JWT_ALG_NONE JWT decoded without algorithm verification config/settings.py:8 HIGH DEBUG_PRODUCTION DEBUG=True in production settings file app/files.py:44 MEDIUM PATH_TRAVERSAL User input used in file path without sanitization app/xml_parser.py:23 MEDIUM XXE_INJECTION XML parser allows external entities [*] Grade: D (7 findings — 2 critical, 3 high, 2 medium) [*] Report saved to vibeguard-report.json Fix these first: app/database.py:34 → Use cursor.execute(query, params) instead of f-strings app/auth.py:12 → Move to environment variable: os.environ.get('API_KEY') What Makes VibeGuard Different From Bandit or Semgrep? Feature VibeGuard Bandit Semgrep Rules built from AI code patterns ✅ ❌ ❌ Letter grade (A–F) ✅ ❌ ❌ Plain English fix for every finding ✅ Partial Partial Detects AI-specific anti-patterns ✅ ❌ ❌ Zero configuration to start ✅ ✅ ❌ CI/CD mode with exit codes ✅ ✅ ✅ VS Code extension Roadmap ❌ ✅ Who Is This For? Developers using Copilot, Cursor, Claude, or ChatGPT to write code Security engineers reviewing AI-generated pull requests Engineering teams who have adopted AI coding tools and want automated security checks DevSecOps teams who want AI-specific security gates in their CI/CD pipeline Students learning about the security implications of AI-generated code Before You Start Check Python is installed python3 --version You need version 3.10 or higher. Check Git is installed git --version Installation # Clone the repo git clone https://github.com/zeroFhacker/vibeguard.git cd vibeguard # Create virtual environment python3 -m venv venv source venv/bin/activate # Windows: venv\Scripts\activate # Install pip install -r requirements.txt Usage Scan a directory PYTHONPATH=. python -m vibeguard.cli scan --path ./my-project Scan a single file PYTHONPATH=. python -m vibeguard.cli scan --path ./app/database.py CI mode — exits with code 1 if findings above threshold PYTHONPATH=. python -m vibeguard.cli scan --path . --ci --fail-on high Show only critical findings PYTHONPATH=. python -m vibeguard.cli scan --path . --severity critical Save report PYTHONPATH=. python -m vibeguard.cli scan --path . --output report.json List all rules PYTHONPATH=. python -m vibeguard.cli rules list The Rule Library — 47 AI-Pattern Rules Category 1: Injection (AI tools love string concatenation) SQL injection via f-string or concatenation Command injection via shell=True LDAP injection XPath injection Template injection Category 2: Secrets (AI tools hardcode everything) API keys assigned to variables Hardcoded passwords in source AWS/GCP/Azure credentials in code Private keys in source files Database connection strings with credentials Category 3: Authentication (AI tools skip the hard parts) JWT decoded without algorithm verification JWT secret hardcoded Weak session secret Missing authentication on sensitive endpoints Insecure password hashing (MD5, SHA1) Category 4: Input Validation (AI tools trust user input) Path traversal via user-controlled file paths XML external entity injection Eval/exec with user input Pickle deserialization of untrusted data YAML load instead of safe_load Category 5: Configuration (AI tools use development defaults) Debug mode enabled in production CORS wildcard origin Insecure cookie settings (no HttpOnly, no Secure) Weak TLS configuration Default admin credentials Category 6: Cryptography (AI tools use deprecated functions) MD5 used for security-sensitive hashing SHA1 used for security-sensitive hashing Weak random (random module) for security values ECB mode encryption Hardcoded encryption key GitHub Actions Integration Add to .github/workflows/security.yml: name: VibeGuard Security Scan on: [push, pull_request] jobs: vibeguard: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-python@v4 with: python-version: '3.11' - run: pip install -r requirements.txt - name: Run VibeGuard run: | PYTHONPATH=. python -m vibeguard.cli scan \ --path . \ --ci \ --fail-on high \ --output vibeguard-report.json - name: Upload report uses: actions/upload-artifact@v4 with: name: vibeguard-security-report path: vibeguard-report.json Understanding the Grade Grade Score What It Means A 90–100 Excellent — no high or critical findings B 75–89 Good — minor issues only C 60–74 Needs attention — several medium findings D 40–59 Poor — high severity findings present F 0–39 Critical — immediate action required Contributing New AI-pattern rules are always welcome. To add a rule: Add a RulePattern to vibeguard/rules/patterns.py Write the regex or AST check Include: name, description, severity, AI tool that commonly produces this, plain English fix Add a test in tests/test_rules.py See CONTRIBUTING.md for full guidance. License MIT — see LICENSE Built by zeroFhacker Part of the open-source security toolkit at github.com/zeroFhacker Resources Readme Activity Stars 1 star Watchers 0 watching Forks 0 forks Report repository