I

I made a dev tool that helps vibecoders to AVOID security issues

Hacker News

I made a dev tool that helps vibecoders to AVOID security issues

The first time I have heard about the vibecoding I could not believe that peeps without the technical background dare to release web apps and other type of software within the week of using such stuff like cursor, claude code and later lovable, bolt.new and etc. I saw some of the projects like that and despite them being somewhat functional - I could feel that security was not the strongest side of these pieces of software. As it turned out I was not hallucinating about the existance of the said security problem - lots of papers were published in this regard. For example, just last quarter 2 prominent papers outlining the problem with stastical approach highlight the severity of security problem within vibecoded apps: 1) https://arxiv.org/abs/2512.03262v1 2) https://arxiv.org/abs/2510.26103 The new itteration of the approach of software development marked a signficant moment of singularity - instead of developers having a deterministic intent mediation process, the developers/vibecoders deploy probabalistic intent mediation when developing applications as outlined in the yet another paper ( https://arxiv.org/abs/2507.21928 ). Probability that the users prompt would correctly enforce the security rules without explicitly knowing security practices is very low and even essentially non existant. So I have built a tool called Vibeshield that works in following way: 1) developer/vibecoder installs mcp server: { "mcpServers": { "vibeshield": { "command": "npx", "args": [ "-y", "vibeshield-mcp@canary" ], "env": { "VIBESHIELD_TOKEN": "vs_live_981bba726786602d91e75be8e9f9a7b7_kSZs-6DPQVtRlSU9qhemEM6HKplvKY59BtUcv0fRbNU" } } } } 2) developer/vibecoder prompts his ai coding agent to create something with the help of vibeshield. For example, he writes: "use vibeshield mcp server. Create/Improve authentification system" 3) user's agent notices that it needs to use analyze_prompt tool which outputs additional security requirements according to the users intent and stack and tells llm how to utilize these requirements. 4) Security requirements are enforced due to the attention that rewritten by mcp server tool prompt is attracting from the perspective llm. 5) As implementation completed - developer/vibecoder would have not only code artifacts but vibeshield docs generated. So if you guys want you can use my token on Ultra plan (see mcp config above) of vibeshield and tell me how it works for you. Note that there are not that many intents - I need to implement more of them with relevant security packs. If you guys are interested in it - you can add me on discord. my username is chockslam. Or you can email me at hello@vibeshield.tech

Share card

Actual performance

1points
Did not reach leaderboard

Launch Intel predictions

Analyze your own launch →
Product HuntOn track for Day 1 leaderboard · Strong signals: agent, cursor, claude · Missing: mac, agents, macos
97%97% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Indie HackersFits the IH revenue-focused audience · Missing: supports, reddit linkedin, podcasting
80%80% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
Hacker NewsStrong engagement from HN community · Strong signals: exist, ide, io · Missing: https docs, excited, just released
51%51% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
TrustMRRLess likely to generate early MRR · Strong signals: apps, users, way · Missing: mobile apps, ios, personal
45%45% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
AppSumoMay struggle as an AppSumo deal · Strong signals: users · Missing: plus, platform, intuitive
33%33% predicted probability of success on AppSumo, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
12%12% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Missing: web3, chat, crypto
0%0% predicted probability of success on BetaList, based on ML models trained on real launch data.

Incorrect prediction on native model

Similar products

To
Tool to Avoid Inflation and Recessions50%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Tool to Avoid Inflation and Recessions

Hacker News1
A
A tool after debugging too many RabbitMQ DLQ issues59%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

A tool after debugging too many RabbitMQ DLQ issues

Hacker News2
Cy
Cybersenshi is officially launched to discover security issues42%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Cybersenshi is officially launched to discover security issues

Hacker News1
Av
Avoid the spinning spikes with ZEP50%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Avoid the spinning spikes with ZEP

Hacker News4
Op
OpalOPC Checks OPC UA for Security Issues46%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

OpalOPC Checks OPC UA for Security Issues

Hacker News1
Cr
Cronk - issues for the commandline47%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Cronk - issues for the commandline

Hacker News1
Bitboard
Bitboard29%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Bitboard helps you organize your Bitbucket issues using boar

Indie Hackers1b2b
Fluffems
Fluffems47%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Fluffems helps you avoid bank fees and late charges

Indie Hackers1b2c
Kloudle
Kloudle74%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Find & Fix 350+ Security Issues In Your Cloud

Indie Hackers1$5,000/moai
To
Top security issues in web applications49%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Top security issues in web applications

Hacker News1