vibe-audit
Free prompt highlights
This prompt doesn't just write the plan.
It audits it until it holds up.
Stop getting plans that read like a paragraph. Read-only until you approve.
Stop briefing Claude every morning.
An automated loop that reads your project files, surfaces what's unfinished, and drops a brief to your working folder before you even wake up. Runs while you sleep so you jump straight into the work.
You're losing context every time you close a tab.
This catches it.
Paste it at the end of any Claude session, the decisions, what got dropped, what's still open, and a clean handoff for the next chat.
vibe-audit
PRE-LAUNCH SECURITY AUDITThis kit answers that question. It's a curated audit your own AI coding tool runs against your codebase. No SaaS, scanner backend or source uploads. You drop the kit into your project, paste a prompt, and your AI walks through 25 findings one at a time, generates a report, and offers to apply fixes.
- 13,000 users exposed across 170 Lovable apps — CVE-2025-48757. Supabase ships Row Level Security disabled by default and the AI didn't turn it on.
- 10.5% of AI-generated code is secure, though 61% is functionally correct — Carnegie Mellon's SusVibes study.
- 2,000+ vulnerabilities and 400+ exposed secrets across 5,600 vibe-coded apps — Escape.tech.
Each covers the specific defaults that bite on that platform.
- LOVABLE Service-role-key-in-client problem. Supabase RLS disabled by default. The pattern behind CVE-2025-48757.
- BOLT WebContainer-vs-deploy gap. Code that runs in the browser editor does not match what ships to production.
- CURSOR Four documented IDE-level CVEs. The tool you're using to write the code has its own attack surface.
- V0 Vercel env scope leakage between Preview and Production. Variables visible where they shouldn't be.
- REPLIT Separate Secrets store for Deployments trap. Secrets in the editor don't automatically carry to deployed builds.
+ The 25-finding catalog with detection prompts and fix prompts
+ Five platform supplements (Lovable, Bolt, Cursor, v0, Replit)
+ A rules file template your AI reads on every turn to stop these patterns being created in the first place
+ A one-shot audit prompt that walks your AI through the catalog and writes a security report into your project
+ 12 months of updates as the patterns evolve and new platforms get added
– A guarantee. No audit is exhaustive. This catches the patterns that have actually taken down vibe-coded apps in production. Real users and regulated data? Hire a pentester.
– A scanner. This isn't a service you upload code to. It runs locally in your own AI session. Your source never leaves your machine.
– A subscription. One-time purchase. Updates included for 12 months, then ongoing-access pricing announced before the 12-month mark.
- STEP 1Buy the kit and download the zip.
- STEP 2Copy the contents of
install/into your project root. Two install modes — drop-at-root or@importfrom an existing rules file. - STEP 3In a fresh AI session, paste:
"Run the security audit defined in AI-AUDIT-CHECKLIST.md. Go through each finding one at a time." - STEP 4Your AI investigates finding by finding, writes a report into
security/REPORT.md, and offers to apply fixes.
Typical audit takes 15 to 45 minutes depending on codebase size and how much your AI has to read.
- + Developers who shipped with Lovable, Bolt, Cursor, v0, or Replit and haven't run a security check before going live with real users.
- + Solo operators without a security background who are deploying apps with real users, real data, or payment flows.
- + Multi-project operators who shipped an AI-built SaaS and want to know what the AI left behind before they go live.
- – Anyone who needs a formal penetration test or audit trail for regulated data. This is the pre-launch sanity check, not the report-of-record. Hire a pentester.
- – Teams with security budgets and pentesters already on retainer. Your needs are different.
- – Anyone looking for prompt packs. This is operating infrastructure.
- Standalone$49
- Loopstack OS add-on$19
- Refund window30 days
- Updates included12 months
The Loopstack OS is launching soon. Buyers receive an add-on code to your original purchase receipt.
<you> how do I actually run the audit?
<luckyd3v> you drop the kit into your project and paste one prompt. your own AI runs the audit against your code and writes the report back into the project.
<luckyd3v> the findings come with fixes, not just flags.
<you> which coding tools does it run in?
<luckyd3v> any tool that reads a project rules file at the root. Claude Code, Cursor, GitHub Copilot, Windsurf and Gemini CLI all have tested patterns in the kit.
<you> how is this different from the free GitHub repos?
<luckyd3v> the foundation overlaps with benavlabs/vibe-check (17 findings, MIT, attributed). beyond that: 8 findings original to this kit, 5 researched platform supplements with CVE citations, a packaged rules file + audit checklist, and 12 months of updates.
<luckyd3v> roughly 75% is original work. the rest is curation and rewriting of public material, attribution kept.
<you> does my code go anywhere?
<luckyd3v> no. everything runs inside your own AI session. the kit is a set of markdown files your AI reads next to your code. no SaaS, scanner backend or upload.
* you are now talking in #vibe-audit
STOP: 0x0000LUCK (0xD3V, 0x00, 0xFREE)
The code has escaped containment. Are you sure you want to ship now? (Y/N)



