VibeDoctor

MCP server that lets Claude Code, Cursor and Codex check their own code: leaked secrets, risky dependencies and common AI-code mistakes, with file and line.

Hosted MCP Server

npx add-mcp 'https://vibedoctor.io/mcp'

Installs into Claude Code, Codex, Cursor and more

Documentation

A second opinion on everything your agent ships.

149+ automated checks across your repo and your deployed site. Secrets, phantom imports, open auth routes, dead performance. One ranked report in under 2 minutes.

Works in

What you get

Scan complete

Overall score

61 /100

Needs attention

Security48

Code quality63

Performance71

356 issues found

AllSecurityCodeSite

  • critical Stripe secret key committed to source lib/payments.ts:14
  • critical
  • high Import of a package that does not exist utils/slugify.ts:2
  • high CORS allows every origin middleware.ts:31
  • medium Same fetch logic duplicated in 6 files components/*

Analyze Riskiest code, ranked

1critical getStripeClient()

11 functions depend on it · 5 fixed, 3 new since last scan

Fix Do this first

Move the Stripe key to an env var

Copy AI fix prompt

V In your agent

Fixed the Stripe key leak and added a rate limit to /api/login. Rescanning now.

16 findings

app api 9 components api/auth 5 lib route.ts

All modules › Api › api/auth 316 features · main 4f2c1ab

Play

  1. 1 Add to cart button AddToCartButton()
  2. 2 Start checkout createCheckoutSession()
  3. 3 Payment confirmed handleStripeWebhook() heads-up: Webhook signature not verified

Operational

Uptime, 30 days 99.98%

Avg response 222 ms

SSL certificate 83 days

Response time

From your last scan SEO 92 Performance 71 Accessibility 88

What it checks

Six things agents get wrong on almost every project.

01 21 checks

Secrets and credentials

API keys, tokens and service credentials committed into source, env files or client bundles.

02 22 checks

Auth and access

Unprotected routes, no rate limit on login or sign up, permissive CORS, sessions that never expire.

03 8 checks

Dependencies

Hallucinated imports, unpinned versions, known CVEs and packages nobody ever installed.

04 29 checks

Vibe coding health

Duplicated logic, dead files, half finished refactors and TODOs the agent promised to come back to.

05 16 checks

Performance

Payload size, render blocking assets, unoptimised images and the requests that make first load crawl.

06 34 checks

SEO and best practices

Metadata, crawlability, accessibility basics and whether an AI search engine can read your pages.

See all 149+ checks across 21 diagnostic areas.

How it works

Paste, scan, fix.

01

Paste one line into your agent

It installs the MCP server itself. Nothing to configure, no dashboard to learn, no keys to paste.

02

Ask it to scan

149+ checks run across your source and your deployed URL in under 2 minutes, public repo or private.

03

Fix it in the same chat

Findings come back ranked with file paths, so the agent that wrote the code can go straight to fixing it.

4%

imported at least one package that does not exist

35%

had API keys or secrets committed to the repo

6%

had no rate limiting on auth endpoints

Measured across

1,099

repos scanned to July 2026

Live scan results

Apps getting checked right now.

Showing the latest 20 of 5,813 scans, including public repos we check around the clock

CountryLanguageFindingsWhen
C#2092 files 1 high 23 medium42m ago
Website3 critical 1 high 1 mediumNot AI Search ReadyCompliant42m ago
🌐JavaScript63 files 16 critical 72 high 42 medium49m ago
🌐TypeScript607 files 2 critical 83 high 241 medium1h ago
🌐TypeScript6 files 1 medium2h ago
🌐Java1 files 1 critical 1 high 6 medium2h ago
Python1370 files 3 high 748 mediumAI Search ReadyCompliant3h ago
Website2 critical 6 mediumNot AI Search ReadyCompliant3h ago
🌐Python102 files 244 medium4h ago
🌐TypeScript1 files 23 medium5h ago
🌐Python33 files 483 medium6h ago
🌐TypeScript527 files 3 critical 6 high 318 medium7h ago
🌐Python142 files 5 critical 43 high 478 medium7h ago
🌐TypeScript172 files 2 critical 4 high 72 medium8h ago
🌐TypeScript1786 files 9 critical 33 high 163 medium9h ago
JavaScript96 files 112 critical 1 high 551 medium9h ago
TypeScript2647 files 21 critical 24 high 1885 mediumAI Search ReadyCompliant10h ago
Python138 files 19 critical 291 mediumAI Search ReadyCompliant10h ago
🌐TypeScript2358 files 12 critical 13 high 201 medium12h ago
Website1 critical 1 high 10 mediumNot AI Search ReadyCompliant13h ago
Website3 critical 8 mediumNot AI Search ReadyNot Compliant13h ago
🌐JavaScript83 files 16 critical 67 high 47 medium13h ago
🌐TypeScript87 files 7 critical 41 high 74 medium14h ago
🌐TypeScript106 files 23 high 70 medium15h ago
Website3 criticalNot AI Search ReadyCompliant23h ago
Website2 critical 5 mediumNot AI Search ReadyCompliant1d ago
Website1 critical 2 high 1 mediumNot AI Search ReadyCompliant1d ago
Website2 high 6 mediumAI Search ReadyCompliant1d ago
Website4 critical 2 high 1 mediumNot AI Search ReadyNot Compliant1d ago
Website3 critical 1 high 5 mediumNot AI Search ReadyCompliant2d ago
Website1 high 36 mediumAI Search ReadyCompliant4d ago
Website2 criticalNot AI Search ReadyCompliant4d ago
Website1 critical 8 mediumNot AI Search ReadyCompliant4d ago
Website1 critical 2 mediumAI Search ReadyNot Compliant4d ago
Website1 critical 6 mediumNot AI Search ReadyCompliant4d ago
Website1 criticalNot AI Search ReadyCompliant4d ago

Vibe X-Ray

See what your agent actually built.

Every scan rebuilds a map of your codebase: modules, the sub-modules inside them, and the files where the findings actually sit. Follow the red down three levels and you land on the file to fix. Paste that one file into your agent instead of the whole repo.

All modules › Api › api/auth X-Ray ready

316 features detected 16 findings main 4f2c1ab 29 connections Sample project

31 18 204 96 47 Api 41 feat / 88 nodes 9 findings / health 38 App 118 feat / 214 nodes 4 findings / health 66 Components 96 feat / 181 nodes 3 findings / health 74 Lib 27 feat / 63 nodes health 91 api/auth 8 feat / 19 nodes 5 findings / health 24 api/stripe 6 feat / 14 nodes 4 findings / health 41 app/(dashboard) 34 feat / 61 nodes 4 findings / health 66 components/forms 22 feat / 38 nodes 3 findings / health 74 lib/db 11 feat / 24 nodes health 91 app/api/login/route.ts critical No rate limiting lib/session.ts high Session never expires app/api/webhook/route.ts critical Signature not verified lib/payments.ts critical Stripe key in source app/(dashboard)/page.tsx medium Missing page metadata components/UploadForm.tsx high No file type check lib/db/client.ts clean no findings

Unhealthy (<60) Fair (60-80) Healthy (>80)

Drill to the function

Module, then sub-module, then the file and the functions inside it. Findings are pinned to the symbol they came from.

Dead code and coverage

Two more tabs on the same map: what nothing calls any more, and which parts of the code no test touches.

Fewer tokens per prompt

Send the files a change actually touches instead of the repo. How Vibe X-Ray works.

On every plan, rebuilt on every scan. See pricing.

Questions.

Is VibeDoctor free?

Yes. Every new account starts with a Free Week: one project, one scan a day, and the full report, with no card required. Paid plans add more projects, a scan on every push, and PR review.

Can VibeDoctor scan a private GitHub repository?

Yes. Connect the GitHub App and access is scoped to read-only. We scan your code, then delete our copy automatically.

Does VibeDoctor modify or write to my code?

No writes. The scan reads your repo and your live site and returns findings. Any fixing happens in your editor, by you or your agent.

How do I connect VibeDoctor to Claude Code, Cursor or Codex?

Paste one line into the agent: connect to vibedoctor using https://vibedoctor.io/mcp/start. It fetches the instructions, installs the MCP server itself, and reports back in the chat you already have open. No keys to copy, no config file to edit.

How is VibeDoctor different from SonarQube, Snyk or CodeRabbit?

There is real overlap. VibeDoctor runs the same classes of engine they do: a SAST pass, secret detection, dependency CVE scanning, and each language's own linter and type checker (opengrep, gitleaks, trivy, ruff, biome, pyright, tsc, clippy, rubocop, phpstan). What it adds is your deployed site scanned alongside the repo (Lighthouse, security headers, SSL, SEO, exposed files, console errors), checks aimed at AI-generated code such as imports of packages that do not exist, and a graph of your codebase. It also runs from inside your agent over MCP, so findings arrive in the chat where the code was written.

4 more questions What languages and frameworks does VibeDoctor scan?

JavaScript and TypeScript, Python, Go, Ruby, Java, PHP and Rust, with framework-aware checks for React, Next.js, Express, Fastify, Django, Flask, FastAPI, Rails and Spring. Anything the site-side checks can reach over HTTP is covered as well.

Is AI-generated code safe to ship?

It usually runs, and it usually ships with the same handful of holes: keys committed to source, auth routes with no guard, missing rate limits, imports of packages that do not exist. This is a scan for people shipping apps their agent mostly wrote, and it finds those before your users do.

How do I find hallucinated npm packages in AI-generated code?

Every scan verifies each dependency against the registry, so an import of a package that does not exist is flagged with its file and line. It is one of the most common AI-generated defects: 4% of the repositories scanned in production had at least one.

What is Vibe X-Ray?

A four-level visual explorer for your codebase: modules, files, symbols and the dependencies between them. It shows what your agent actually built - which functions call what, where complexity hides, and what breaks if you touch something. It updates with every scan.

Scan it before your users do.

connect to vibedoctor using https://vibedoctor.io/mcp/start

Or paste a repo URL and skip the setup entirely.

Someone in Norway scanned their app

24 issues found · scored 93/100