VibeDoctor
MCP server that lets Claude Code, Cursor and Codex check their own code: leaked secrets, risky dependencies and common AI-code mistakes, with file and line.
Hosted MCP Server
npx add-mcp 'https://vibedoctor.io/mcp'Installs into Claude Code, Codex, Cursor and more
Documentation
A second opinion on everything your agent ships.
149+ automated checks across your repo and your deployed site. Secrets, phantom imports, open auth routes, dead performance. One ranked report in under 2 minutes.
Works in
What you get
Scan complete
Overall score
61 /100
Needs attention
Security48
Code quality63
Performance71
356 issues found
AllSecurityCodeSite
- critical
Stripe secret key committed to source
lib/payments.ts:14 - critical
- high
Import of a package that does not exist
utils/slugify.ts:2 - high
CORS allows every origin
middleware.ts:31 - medium
Same fetch logic duplicated in 6 files
components/*
Analyze Riskiest code, ranked
1critical getStripeClient()
11 functions depend on it · 5 fixed, 3 new since last scan
Fix Do this first
Move the Stripe key to an env var
Copy AI fix prompt
V In your agent
Fixed the Stripe key leak and added a rate limit to /api/login. Rescanning now.
16 findings
app api 9 components api/auth 5 lib route.ts
All modules › Api › api/auth 316 features · main 4f2c1ab
Play
- 1
Add to cart button
AddToCartButton() - 2
Start checkout
createCheckoutSession() - 3
Payment confirmed
handleStripeWebhook()heads-up: Webhook signature not verified
Operational
Uptime, 30 days 99.98%
Avg response 222 ms
SSL certificate 83 days
Response time
From your last scan SEO 92 Performance 71 Accessibility 88
What it checks
Six things agents get wrong on almost every project.
01 21 checks
Secrets and credentials
API keys, tokens and service credentials committed into source, env files or client bundles.
02 22 checks
Auth and access
Unprotected routes, no rate limit on login or sign up, permissive CORS, sessions that never expire.
03 8 checks
Dependencies
Hallucinated imports, unpinned versions, known CVEs and packages nobody ever installed.
04 29 checks
Vibe coding health
Duplicated logic, dead files, half finished refactors and TODOs the agent promised to come back to.
05 16 checks
Performance
Payload size, render blocking assets, unoptimised images and the requests that make first load crawl.
06 34 checks
SEO and best practices
Metadata, crawlability, accessibility basics and whether an AI search engine can read your pages.
See all 149+ checks across 21 diagnostic areas.
How it works
Paste, scan, fix.
01
Paste one line into your agent
It installs the MCP server itself. Nothing to configure, no dashboard to learn, no keys to paste.
02
Ask it to scan
149+ checks run across your source and your deployed URL in under 2 minutes, public repo or private.
03
Fix it in the same chat
Findings come back ranked with file paths, so the agent that wrote the code can go straight to fixing it.
4%
imported at least one package that does not exist
35%
had API keys or secrets committed to the repo
6%
had no rate limiting on auth endpoints
Measured across
1,099
repos scanned to July 2026
Live scan results
Apps getting checked right now.
Showing the latest 20 of 5,813 scans, including public repos we check around the clock
| Country | Language | Findings | When |
|---|---|---|---|
| C# | 2092 files 1 high 23 medium | 42m ago | |
| Website | 3 critical 1 high 1 mediumNot AI Search ReadyCompliant | 42m ago | |
| 🌐 | JavaScript | 63 files 16 critical 72 high 42 medium | 49m ago |
| 🌐 | TypeScript | 607 files 2 critical 83 high 241 medium | 1h ago |
| 🌐 | TypeScript | 6 files 1 medium | 2h ago |
| 🌐 | Java | 1 files 1 critical 1 high 6 medium | 2h ago |
| Python | 1370 files 3 high 748 mediumAI Search ReadyCompliant | 3h ago | |
| Website | 2 critical 6 mediumNot AI Search ReadyCompliant | 3h ago | |
| 🌐 | Python | 102 files 244 medium | 4h ago |
| 🌐 | TypeScript | 1 files 23 medium | 5h ago |
| 🌐 | Python | 33 files 483 medium | 6h ago |
| 🌐 | TypeScript | 527 files 3 critical 6 high 318 medium | 7h ago |
| 🌐 | Python | 142 files 5 critical 43 high 478 medium | 7h ago |
| 🌐 | TypeScript | 172 files 2 critical 4 high 72 medium | 8h ago |
| 🌐 | TypeScript | 1786 files 9 critical 33 high 163 medium | 9h ago |
| JavaScript | 96 files 112 critical 1 high 551 medium | 9h ago | |
| TypeScript | 2647 files 21 critical 24 high 1885 mediumAI Search ReadyCompliant | 10h ago | |
| Python | 138 files 19 critical 291 mediumAI Search ReadyCompliant | 10h ago | |
| 🌐 | TypeScript | 2358 files 12 critical 13 high 201 medium | 12h ago |
| Website | 1 critical 1 high 10 mediumNot AI Search ReadyCompliant | 13h ago | |
| Website | 3 critical 8 mediumNot AI Search ReadyNot Compliant | 13h ago | |
| 🌐 | JavaScript | 83 files 16 critical 67 high 47 medium | 13h ago |
| 🌐 | TypeScript | 87 files 7 critical 41 high 74 medium | 14h ago |
| 🌐 | TypeScript | 106 files 23 high 70 medium | 15h ago |
| Website | 3 criticalNot AI Search ReadyCompliant | 23h ago | |
| Website | 2 critical 5 mediumNot AI Search ReadyCompliant | 1d ago | |
| Website | 1 critical 2 high 1 mediumNot AI Search ReadyCompliant | 1d ago | |
| Website | 2 high 6 mediumAI Search ReadyCompliant | 1d ago | |
| Website | 4 critical 2 high 1 mediumNot AI Search ReadyNot Compliant | 1d ago | |
| Website | 3 critical 1 high 5 mediumNot AI Search ReadyCompliant | 2d ago | |
| Website | 1 high 36 mediumAI Search ReadyCompliant | 4d ago | |
| Website | 2 criticalNot AI Search ReadyCompliant | 4d ago | |
| Website | 1 critical 8 mediumNot AI Search ReadyCompliant | 4d ago | |
| Website | 1 critical 2 mediumAI Search ReadyNot Compliant | 4d ago | |
| Website | 1 critical 6 mediumNot AI Search ReadyCompliant | 4d ago | |
| Website | 1 criticalNot AI Search ReadyCompliant | 4d ago |
Vibe X-Ray
See what your agent actually built.
Every scan rebuilds a map of your codebase: modules, the sub-modules inside them, and the files where the findings actually sit. Follow the red down three levels and you land on the file to fix. Paste that one file into your agent instead of the whole repo.
All modules › Api › api/auth X-Ray ready
316 features detected 16 findings main 4f2c1ab 29 connections Sample project
31 18 204 96 47 Api 41 feat / 88 nodes 9 findings / health 38 App 118 feat / 214 nodes 4 findings / health 66 Components 96 feat / 181 nodes 3 findings / health 74 Lib 27 feat / 63 nodes health 91 api/auth 8 feat / 19 nodes 5 findings / health 24 api/stripe 6 feat / 14 nodes 4 findings / health 41 app/(dashboard) 34 feat / 61 nodes 4 findings / health 66 components/forms 22 feat / 38 nodes 3 findings / health 74 lib/db 11 feat / 24 nodes health 91 app/api/login/route.ts critical No rate limiting lib/session.ts high Session never expires app/api/webhook/route.ts critical Signature not verified lib/payments.ts critical Stripe key in source app/(dashboard)/page.tsx medium Missing page metadata components/UploadForm.tsx high No file type check lib/db/client.ts clean no findings
Unhealthy (<60) Fair (60-80) Healthy (>80)
Drill to the function
Module, then sub-module, then the file and the functions inside it. Findings are pinned to the symbol they came from.
Dead code and coverage
Two more tabs on the same map: what nothing calls any more, and which parts of the code no test touches.
Fewer tokens per prompt
Send the files a change actually touches instead of the repo. How Vibe X-Ray works.
On every plan, rebuilt on every scan. See pricing.
Questions.
Is VibeDoctor free?
Yes. Every new account starts with a Free Week: one project, one scan a day, and the full report, with no card required. Paid plans add more projects, a scan on every push, and PR review.
Can VibeDoctor scan a private GitHub repository?
Yes. Connect the GitHub App and access is scoped to read-only. We scan your code, then delete our copy automatically.
Does VibeDoctor modify or write to my code?
No writes. The scan reads your repo and your live site and returns findings. Any fixing happens in your editor, by you or your agent.
How do I connect VibeDoctor to Claude Code, Cursor or Codex?
Paste one line into the agent: connect to vibedoctor using https://vibedoctor.io/mcp/start. It fetches the instructions, installs the MCP server itself, and reports back in the chat you already have open. No keys to copy, no config file to edit.
How is VibeDoctor different from SonarQube, Snyk or CodeRabbit?
There is real overlap. VibeDoctor runs the same classes of engine they do: a SAST pass, secret detection, dependency CVE scanning, and each language's own linter and type checker (opengrep, gitleaks, trivy, ruff, biome, pyright, tsc, clippy, rubocop, phpstan). What it adds is your deployed site scanned alongside the repo (Lighthouse, security headers, SSL, SEO, exposed files, console errors), checks aimed at AI-generated code such as imports of packages that do not exist, and a graph of your codebase. It also runs from inside your agent over MCP, so findings arrive in the chat where the code was written.
4 more questions What languages and frameworks does VibeDoctor scan?
JavaScript and TypeScript, Python, Go, Ruby, Java, PHP and Rust, with framework-aware checks for React, Next.js, Express, Fastify, Django, Flask, FastAPI, Rails and Spring. Anything the site-side checks can reach over HTTP is covered as well.
Is AI-generated code safe to ship?
It usually runs, and it usually ships with the same handful of holes: keys committed to source, auth routes with no guard, missing rate limits, imports of packages that do not exist. This is a scan for people shipping apps their agent mostly wrote, and it finds those before your users do.
How do I find hallucinated npm packages in AI-generated code?
Every scan verifies each dependency against the registry, so an import of a package that does not exist is flagged with its file and line. It is one of the most common AI-generated defects: 4% of the repositories scanned in production had at least one.
What is Vibe X-Ray?
A four-level visual explorer for your codebase: modules, files, symbols and the dependencies between them. It shows what your agent actually built - which functions call what, where complexity hides, and what breaks if you touch something. It updates with every scan.
Scan it before your users do.
connect to vibedoctor using https://vibedoctor.io/mcp/start
Or paste a repo URL and skip the setup entirely.
Someone in Norway scanned their app
24 issues found · scored 93/100