Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Windows Tipps & SecurityWindows-Update beschädigt wichtige Datenrettungsfunktion(22.09.2026 um 09:04 Uhr)
Sichere ProgrammierungBuilding an Accessible Ecommerce Product Page with WCAG 2.2(22.09.2026 um 03:39 Uhr)
Sichere ProgrammierungGet Your Website Protected in 10 Minutes with SafeLine WAF(22.09.2026 um 08:42 Uhr)
Sichere ProgrammierungIntroduction to SPRINGBOOT(22.09.2026 um 08:42 Uhr)
Windows Tipps & SecurityWindows-Update beschädigt wichtige Datenrettungsfunktion(22.09.2026 um 09:04 Uhr)
Sichere ProgrammierungBuilding an Accessible Ecommerce Product Page with WCAG 2.2(22.09.2026 um 03:39 Uhr)
Sichere ProgrammierungGet Your Website Protected in 10 Minutes with SafeLine WAF(22.09.2026 um 08:42 Uhr)
Sichere ProgrammierungIntroduction to SPRINGBOOT(22.09.2026 um 08:42 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Add Security Scanning to Any GitHub Repo in 3 Lines of YAML

AI writes code fast. It also writes the same security bugs, over and over. We scanned 10 popular vibe-coded repos (10k–100k ⭐) last week. Every single one had at least one critical issue that passed code review undetected. The most com…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

AI writes code fast. It also writes the same security bugs, over and over.



We scanned 10 popular vibe-coded repos (10k–100k ⭐) last week. Every single one had at least one critical issue that passed code review undetected.



The most common pattern:




# AI generates this constantly
def save_user(data):
return {"status": "saved"} # No actual DB write. Ever.

async def fetch_profile(user_id):
return profile # async keyword, zero await calls






These aren't typos. They're structural patterns that emerge when LLMs write code — and standard linters miss all of them.









We built a scanner that catches them



AINAScan / VibeGuard — AST-based, deterministic, no LLM involved. 48 patterns across 9 languages.



And now it's a GitHub Action.









Add it to your repo in 3 lines






# .github/workflows/vibeguard.yml
name: Security Scan
on: [pull_request]

jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: Moonsehwan/aina-vibeguard-action@v1
with:
api-key: ${{ secrets.VIBEGUARD_KEY }}






Add VIBEGUARD_KEYSettings → Secrets → Actions → New secret



Use vg_free_test as the value (free promo key, valid until June 24).



That's it. Every PR now gets scanned. Critical issues fail the check automatically.









What it actually catches






Security patterns (33)




  • SQL injection via f-strings

  • Path traversal from unvalidated input

  • Command injection in subprocess calls

  • Hardcoded API keys and passwords

  • SSRF, XSS, eval/exec risks






Vibe-coding patterns (15) — unique to AINAScan
































Pattern What it means
MISSING_WRITE
save_user() with no INSERT/UPDATE anywhere
FAKE_ASYNC
async def with zero await calls
STUB_SKELETON Function body is just return {}
DEAD_CALL_RESULT Calls 3 modules, ignores all return values
INPUT_OUTPUT_DISCONNECTED Parameters don't affect the return value


These patterns are in no other scanner. They exist because AI coding assistants repeat them constantly.









Real finding from last week



Scanned serena (25k ⭐) — a popular AI coding assistant:




[BLOCK] COMMAND_INJECTION  agent.py:1222
subprocess.Popen(cmd, shell=True)
any config value can execute arbitrary shell commands






Found in 3 seconds. Missed by the maintainers.









Use the output in your agent workflow



The API returns structured JSON, so AI agents can auto-fix:




result = requests.post(
"https://pleasing-transformation-production-90c2.up.railway.app/v1/scan",
headers={"X-API-Key": "vg_free_test"},
files={"file": open("app.py", "rb")}
).json()

# Pass to Claude/GPT for auto-fix
if not result["passed"]:
prompt = f"Fix these issues: {result['issues']}"
fixed = agent.generate(prompt)












Try it now



Free key (until June 24): vg_free_test




curl -X POST https://pleasing-transformation-production-90c2.up.railway.app/v1/scan \
-H "X-API-Key: vg_free_test" \
-F "file=@your_file.py"






GitHub Action: Moonsehwan/aina-vibeguard-action

Full docs: github.com/Moonsehwan/aina-scan






Would love to hear what patterns you're seeing in your AI-generated code. Drop them in the comments — if it's a real pattern we're not catching, we'll add it.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Add Security Scanning to Any GitHub Repo in 3 Lines of YAML

Thematisch verwandte Begriffe: Security, Scanning, GitHub, Repo · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-55210 | Joplin is an open source note-taking and to-do application that organise…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick