nerua1-vibe-safeSecurity pre-flight for AI coding agents — plan libs, audit CVEs, certify, then code. Non-blocking in autonomous mode (ex-post report).
Install via ClawdBot CLI:
clawdbot install nerua1/nerua1-vibe-safeGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://api.osv.dev/v1/queryCalls external URL not in known-safe list
https://api.osv.dev/v1/queryUses known external API (expected, informational)
api.github.comAI Analysis
The skill queries the OSV (Open Source Vulnerabilities) API to check for known CVEs in proposed libraries, which is consistent with its stated security audit purpose. The GitHub API call is also for legitimate dependency checking. No user credentials, secrets, or sensitive data are sent to these endpoints — only package/library names and versions. The skill explicitly mandates secrets policy (env files, .gitignore) and does not exfiltrate or override user intent.
Generated Oct 6, 2026
A platform team integrates VibeSafe into its Claude Code and Cursor workflows so every AI-generated pull request that introduces dependencies triggers an automatic CVE audit, license check, and risk report. Developers receive a `risk-report.md` in the PR, and critical findings block merges until a human waives the risk. This keeps vibe-coding velocity while introducing a security pre-flight gate.
An AI agent building a SaaS product overnight uses VibeSafe in autonomous mode to audit every library it installs, then appends a `risk-report.md` to the session output. In the morning, the founder reviews the report, resolves high-severity CVEs, and renews the lockfile before deploying. This prevents the agent from silently shipping vulnerable dependencies.
A fintech company requires every AI-generated service to pass VibeSafe's Phase 1 threat model and secret policy declaration before any code is written. The security team uses OSV.dev and deps.dev checks to enforce supply-chain policies, and all waivers are logged in `stay_safe.md` for audit trails. This helps meet SOC 2 and internal risk controls for new third-party libraries.
A popular open-source node package uses VibeSafe as a contribution pre-flight: AI contributors must run the audit before submitting PRs that add dependencies. The resulting risk report is posted as a PR comment, and maintainers can quickly assess supply-chain risk without manual investigation. This scales security review across a high volume of AI-assisted contributions.
A health-tech company uses VibeSafe when AI coding agents add libraries to its patient-data services. The mandatory secrets policy prevents API keys from entering source code, and CVE audits ensure dependencies meet HIPAA-adjacent security standards. Findings are stored in the session output for compliance audits.
Offer VibeSafe as a free CLI/plugin for individual developers with core OSV.dev auditing, while charging for team features like centralized dashboards, policy enforcement, and audit logs. The free tier drives adoption among vibe coders, and paid teams convert as they need governance.
Host VibeSafe as a cloud API that AI agent platforms and IDE vendors call before allowing dependency installation. The service returns a risk score and actionable fixes, replacing or augmenting local static checks. Revenue comes from API call volume and platform integration fees.
Sell VibeSafe as a compliance module inside larger DevSecOps suites, with custom threat models and regulatory mappings (SOC 2, HIPAA, PCI). Enterprises pay for private deployment, SSO, and auditor-ready reporting on AI-generated code. This targets regulated industries needing traceable AI coding governance.
💬 Integration Tip
Wrap VibeSafe as a pre-commit or CI hook and auto-post the `risk-report.md` to pull requests or agent session outputs, so security checks run automatically without breaking developer flow.
Scored Oct 6, 2026
Audited May 10, 2026 · audit v1.0
Control desktop applications on Windows — launch, close, focus, resize, move windows, simulate keyboard/mouse input, manage processes, control VSCode, read clipboard, and capture screen info. Use when the user wants to interact with any running program, switch windows, type text, press shortcuts, open files in VSCode, manage running processes, or get system display information.
Conduct rigorous, adversarial code reviews with zero tolerance for mediocrity. Use when users ask to "critically review" my code or a PR, "critique my code", "find issues in my code", or "what's wrong with this code". Identifies security holes, lazy patterns, edge case failures, and bad practices across Python, R, JavaScript/TypeScript, SQL, and front-end code. Scrutinizes error handling, type safety, performance, accessibility, and code quality. Provides structured feedback with severity tiers (Blocking, Required, Suggestions) and specific, actionable recommendations.
Pragmatic coding standards for writing clean, maintainable code — naming, functions, structure, anti-patterns, and pre-edit safety checks. Use when writing new code, refactoring existing code, reviewing code quality, or establishing coding standards.
Claude Code integration for OpenClaw. This skill provides interfaces to: - Query Claude Code documentation from https://code.claude.com/docs - Manage subagents and coding tasks - Execute AI-assisted coding workflows - Access best practices and common workflows Use this skill when users want to: - Get help with coding tasks - Query Claude Code documentation - Manage AI-assisted development workflows - Execute complex programming tasks
Plan, draft, version, and refine written content with enforced versioning and quality audits.
Use when writing tests, creating test strategies, or building automation frameworks. Invoke for unit tests, integration tests, E2E, coverage analysis, performance testing, security testing.