Vibecheck is an MCP server that provides automated security analysis and browser-based testing workflows for AI coding assistants. It connects development environments such as Cursor, GitHub Copilot, Windsurf, and Claude Code with static analysis tools, dynamic security checks, and browser automation drivers. Software engineers and AI developers use it to analyze code snippets for common vulnerabilities like SQL injection and cross-site scripting before commits occur. Beyond static analysis with engines like Semgrep, the server automates end-to-end web testing by leveraging Playwright and LLM-driven planning. It enables users to record test scripts using natural language instructions, execute recorded JSON test suites, discover potential test steps across web pages, and perform visual regression checks. By communicating directly through the Model Context Protocol, Vibecheck delivers vulnerability reports, execution logs, and remediation guidance straight back to the assistant, establishing a continuous security feedback loop throughout development.
Category: Other & General Purpose
Tags: experimental, general, utility
git clone https://github.com/Ilikepizza2/VibeCheck and enter the directory. 2. Create and activate a Python virtual environment. 3. Install dependencies using pip install -r requirements.txt and install browsers with patchright install --with-deps. 4. Copy .env.example to .env and configure LLM_API_KEY. 5. Add the server configuration to your MCP client config: json { "mcpServers": { "VibeShift": { "command": "uv", "args": ["--directory", "path/to/cloned_repo", "run", "mcp_server.py"] } } }Part of MCP Servers
Clone the repository from GitHub, create a Python virtual environment, and install the required dependencies using pip. Run patchright install to download necessary browser binaries, set your LLM API key inside a .env file, and register mcp_server.py inside your MCP client configuration file using uv.
Vibecheck performs static code analysis on AI-generated code using Semgrep, identifies security vulnerabilities such as XSS or SQL injection, and delivers remediation feedback to your AI client. It also controls Playwright to record end-to-end tests from natural language, execute regression runs, crawl web pages, and perform visual regression checks.
Vibecheck works with any Model Context Protocol compliant client or AI coding assistant. Documented examples include Cursor, Windsurf, GitHub Copilot, and Roo Code, as well as Claude Desktop.
Yes, Vibecheck is open-source software distributed under the Apache-2.0 license, with source code available on GitHub.