VibeSafe
VibeSafe scans repositories for security problems, posts findings on pull requests, and fails CI when it finds critical vulnerabilities. Built in collaboration with Humza Hassan.
- 51 rules / 10 vulnerability categories
- Fails CI on critical findings

What it’s for
VibeSafe checks code where it’s being reviewed. It looks for security problems in repositories and pull requests, then reports what it finds.
How I built it
The Python scanner combines regex checks and configuration parsing with deeper Claude analysis across 51 rules and 10 vulnerability categories. FastAPI provides the interface, Docker packages the service, and GitHub Actions connects scans to pull requests.
What it does
It posts findings directly on pull requests. Critical vulnerabilities fail CI, making the result part of the review workflow rather than a separate report.
The interesting part
The interesting part is combining checks that follow fixed rules with LLM analysis. Severity then determines whether CI should fail.
Industry Resilience Predictor
HAVE A QUESTION OR AN IDEA?