Secure Vibe Coding

Security co-pilot for AI-assisted rapid development (vibe coding) sessions. Activates a set of non-negotiable security guardrails that run alongside every code generation, preventing the classic vibe-coding failure modes: hardcoded secrets, disabled auth guards, raw SQL from user input, unvalidated outbound URLs, and stack-trace leakage in API responses. Invoke this skill at the START of any vibe coding session, or when the user says "let's go fast", "just ship it", "vibe coding mode", "speed run this", "skip the boilerplate", "secure vibe coding", "vibe with guardrails", or "keep me secure while we build fast". ALSO trigger whenever Claude is about to generate code that touches auth, database queries, HTTP clients, file uploads, or API responses — these are the five zones where speed kills security. The goal is not to slow down: it is to eliminate the security rework that happens after shipping insecure code fast. When this skill is active, do NOT produce a separate security report after code generation — th

xuanjgcarryyou Updated

File contents

xuanjgcarryyou/claude-skill/tree/main/.claude/skills/secure-vibe-coding commit d5eb24892a

Frequently asked questions

npx skillmds@latest add xuanjgcarryyou/secure-vibe-coding