vibe-audit-technique
Installation
SKILL.md
vibe-audit-technique
Goal: Identify critical, high-frequency security omissions in modern web/mobile stacks (Next.js, Firebase, Supabase, Vite, Expo) that are typically generated by AI coding assistants (Lovable, Bolt.new, v0, Cursor, Replit Agent, Claude Code).
When this technique applies
- You have source-code access to a modern web application or mobile app backend.
- The stack relies heavily on BaaS (Backend-as-a-Service) like Supabase, Firebase, or Clerk.
- You are reviewing Next.js Server Actions, tRPC routers, React Server Components, or Expo/React Native apps.
- The repo shows AI-generator fingerprints (Lovable/Bolt/v0/Cursor commit messages, one-shot scaffolded migrations,
.cursor/,mcp.json,.bolt/).
Pair with sibling techniques
- For LLM-assisted taint tracing from source to sink across large repos, drive the pass with
offensive-techniques/source-review-technique/SKILL.md. This skill supplies the vibe-code sink catalogue; that skill supplies the AI-assisted data-flow discipline. - Do not re-derive general SAST here.