goklab/guardvibe
MCP Security & AuthA deterministic security verification layer that watches AI‑generated code in real time, catches post‑cutoff CVEs, scans the whole repository context, and can even audit prompts before any code is written.
Features
- Real‑time, content‑hashed scanning of AI‑written code across an entire repo
- Daily refreshed CVE intelligence from GHSA, OSV.dev, and CISA KEV (83 rules)
- Pre‑prompt security analysis (`secure_prompt`) that blocks vulnerabilities before code generation
- Zero‑setup local execution via `npx guardvibe` with no required accounts or API keys
- Auto‑fix suggestions for common issues like hardcoded credentials, CORS wildcards, and sandbox bypass flags
Recent releases
View all 150 releases →
Upgrade now
v3.29.0
Security relevant
RCE / SSRF
Dependencies
Breaking upgrade
CVE-2026-49252 + CVE-2026-55698
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
About
Stars
4
Forks
0
Languages
TypeScript
JavaScript
Downloads/week
720
↓21%
NPM Maintainers
1
Single npm maintainer
Contributors
3
TypeScript
Types included ✓
Install & Platforms
Install via
npm