Back to my projects

VibeSafe

VibeSafe scans repositories for security problems, posts findings on pull requests, and fails CI when it finds critical vulnerabilities. Built in collaboration with Humza Hassan.

  • 51 rules / 10 vulnerability categories
  • Fails CI on critical findings
PythonClaude APIFastAPIDockerGitHub Actions
MY WORK

Security scanner development

YEAR

2026

VibeSafe website: Ship code fearlessly, with AI-powered security scanning.
/01

What it’s for

VibeSafe checks code where it’s being reviewed. It looks for security problems in repositories and pull requests, then reports what it finds.

/02

How I built it

The Python scanner combines regex checks and configuration parsing with deeper Claude analysis across 51 rules and 10 vulnerability categories. FastAPI provides the interface, Docker packages the service, and GitHub Actions connects scans to pull requests.

/03

What it does

It posts findings directly on pull requests. Critical vulnerabilities fail CI, making the result part of the review workflow rather than a separate report.

/04

The interesting part

The interesting part is combining checks that follow fixed rules with LLM analysis. Severity then determines whether CI should fail.

NEXT PROJECT / 04

Industry Resilience Predictor

HAVE A QUESTION OR AN IDEA?

Want to
talk code?

I’d be glad to hear from you.

UNC Chapel Hill