VibeKit

Security

Agent First security review with evidence before release.

VibeKit implements the repository-level parts of OpenAI's Defense Factory recommendations that fit a SaaS boilerplate.

That means VibeKit uses shared security context, reusable Agent Skills, existing CLI security tools and disposable local environments to find, validate and verify security work.

It does not claim to include OpenAI's full enterprise Defense Factory control plane, asset inventory, findings database or specialized cyber models.

What VibeKit implements

  • docs/security/ gives agents durable application-security and trust-boundary context.
  • security-review runs threat modeling, coverage, finding discovery, validation and attack-path review.
  • bun audit and the secret scanner feed candidate evidence into the review.
  • Disposable local setup gives the agent a safer place to reproduce suspected issues.
  • Findings need evidence before they are treated as real vulnerabilities.
  • Confirmed fixes return to the owning feature or package and finish with verify-changes.
  • A local patch is not treated as a deployed fix. Production retesting is separate and requires approval.

This keeps the useful Defense Factory loop inside the repository without adding company-scale infrastructure that does not belong in an application template.

Run a security review

Give your coding agent this prompt:

Use $security-review to run a repository-wide security review of this VibeKit checkout.

Read docs/security/index.md and the relevant threat-model context first. Review the important trust boundaries before chasing individual findings. Use the existing dependency and secret checks as supporting evidence.

Validate plausible findings against source, existing tests and disposable local services when safe. Separate confirmed findings, rejected candidates and anything that still needs proof.

Do not change product code while scanning. If I approve fixes afterward, use the owning implementation skill for each finding and finish each fix with $verify-changes.

What the review focuses on

The workflow prioritizes identity, Team isolation, admin authority, MCP grants, payments, storage, provider secrets, AI data and authority boundaries, destructive data operations and other high-impact request paths.

For each finding the agent should show the attacker path, failed control, impact, evidence, counterevidence, severity, confidence and smallest safe fix.

A clean scan is not a promise that software has no vulnerabilities. It means the reviewed surfaces were checked under the stated scope and evidence limits.

Before launch

The VibeKit product workflow treats security-review as the dedicated security check before launch. Any reportable finding or unresolved high-impact security gate should remain open until it is fixed, accepted explicitly or proven not applicable.

The goal is simple: discover issues early, validate them before creating noise and verify the fix before calling the security work complete.

On this page