Local-first · read-only · nothing leaves your machine

Your RLS is on. We still read your data.

You didn't vibe-code one app — you shipped a pile of them with Lovable, Bolt, v0 and Cursor. Public apps and the internal CRMs, dashboards and inventory tools you built for yourself — each one's another live key to remember. Ms. Vibecode runs the breach on every project: it grabs the public key from each frontend and actually tries to read your tables, catches the secrets leaking into your live bundles, then hands you the exact prompt to fix each one. All your projects in one dashboard — read-only, on your machine. The one you forgot about is the one that's exposed.

14-day free trial · no signup · no cloud account · macOS & Windows

ms-vibecode · audit · your-app
HIGH

2 tables are readable with your public key

users (read 1 row), orders (read 1 row) — RLS is on, but a policy allows anonymous reads.

CRITICAL

Stripe secret key exposed in your live bundle

Found sk_live_… in the JavaScript served at app.js.

This isn't hypothetical

The leak we check for is the one breaching real apps

Security firm Escape scanned 5,600 live vibe-coded apps. What they found is the exact class of exposure Ms. Vibecode checks for — sitting in production.

175

apps caught leaking real personal data — medical records and bank account numbers — reachable straight from production.

Escape.tech, scan of 5,600 vibe-coded apps · Oct 2025
400+

exposed API keys and secrets in that same scan — the kind that ship in your frontend bundle, readable by anyone who views source.

Escape.tech, scan of 5,600 vibe-coded apps · Oct 2025

And it's a known, registered vulnerability — CVE-2025-48757 documents Lovable apps exposing user data through exactly the Row Level Security misconfiguration we check first.

Why one scan isn't enough

The app you forgot about is the one that's leaking

You didn't build one thing. You've shipped a pile of projects across Supabase, Vercel, GitHub and Stripe — each wired to live keys you haven't thought about in months. Your project count keeps climbing; your memory doesn't.

Every project, one dashboard

Supabase, Vercel, GitHub and Stripe across all your apps in a single view — the cross-stack picture no single platform will build for you, because each one only sees its own.

Re-run the breach any time

Shipped a change, or just haven't looked in a while? Re-run the same read-only audit across your projects and see exactly what moved — on your machine, whenever you want.

The forgotten one, surfaced

Your real exposure isn't the app you're building today — it's the one you launched eight months ago, wired to a live key, and never opened again. This is the place that keeps it in view.

Audit every project

We prove the breach — we don't just read a flag

Supabase's dashboard tells you a switch is on. That misses the case that actually leaks vibe-coded apps: RLS on, but a policy quietly leaves the door open. Ms. Vibecode fetches the public key that ships in your frontend and tries the door.

Reads your data with your public key

It runs the exact request a stranger could — “read 1 row from posts using only your anon key” — catching Row Level Security left off and the permissive policies a config check sails past.

Finds anonymous write access

Inspects your policies for tables the public role can insert, update or delete — and separates a truly open policy from the standard auth.uid() pattern. Read-only; no write is ever attempted.

Catches secrets in your live site

Scans your deployed bundle for sk_live_, service-role keys and private keys — while ignoring the publishable keys that are meant to be public, so it never cries wolf.

Find → fix

It doesn't just find the problem — it hands you the fix

You vibe-coded the app; you shouldn't have to become a security engineer to close the hole. Every fixable finding comes with a copy-paste prompt built for your AI coding tool: click Copy AI fix prompt, paste it into Cursor or Claude Code, and it makes the change in your codebase. The audit already did the hard part — the fix is one paste away.

A Ms. Vibecode audit result showing two high-severity Supabase findings — tables readable with the public key, and public storage buckets — each with a 'Copy AI fix prompt' button next to a 'How to fix' link, plus green passing checks for Row Level Security and email confirmation. The specific table and bucket names are redacted with grey bars.
Every fixable finding gets a one-click prompt you paste straight into your AI. (Table & bucket names redacted.)

This isn't a penetration test. A clean run means no known misconfigurations found — not a guarantee. Every finding ships with the evidence — and a copy-paste prompt you drop straight into Cursor or Claude Code to fix it.

Built for internal tools too

The CRM you built for yourself is the scariest one

You vibe-coded your own CRM, inventory tracker or admin panel and figured "it's internal, nobody knows the URL, it's fine." But it deploys to the same public Supabase and Vercel as everything else — so security-through-obscurity is its default state. That's not security; it's a bet that nobody guesses the link. Ms. Vibecode runs every one of its checks on your internal tools too — and this is exactly where they matter most.

Your customer list, read with the public key

The same anon key that ships in your tool's frontend can often read the whole customers table. Ms. Vibecode runs that exact request — the internal-tool breach, proven in a single read.

Anyone can register into it

Left email confirmation off? A stranger can create an account in your "internal" admin panel under any address. We flag the setting that leaves the door open.

Records anyone can change

An open write policy lets the public role edit or delete your inventory and order rows. We catch the ungated ones — read-only, no write is ever attempted.

Deployed to public infra like Vercel or Supabase? Every check above already applies — same engine, same read-only breach. A tool that's genuinely air-gapped (localhost, VPN or corporate SSO, never publicly deployed) is out of reach for a remote check — and is mostly already protected by that isolation.

When something breaks

Answers, not another dashboard

You vibe-coded the app; you shouldn't need to be a backend engineer to fix it. Ms. Vibecode points straight at the failing piece — and stops you shipping a secret you'd regret.

A Ms. Vibecode project view: a Stack Profile reading 'an AI-powered static or frontend site', with per-service cards showing Claude and GitHub healthy, their API keys masked to the last four characters, and a plain-language note on what each check does.

Is it your key, or your code?

When something breaks, you shouldn't have to guess. Hit check and Ms. Vibecode makes a real authenticated call to each provider, then tells you in plain English whether the key works, the service is down, or the problem is somewhere in your code.

Catch leaked secrets before you deploy

Pick your framework — Vite, Next.js, Astro, SvelteKit — and Ms. Vibecode flags any secret wearing a browser-exposed prefix like VITE_ or NEXT_PUBLIC_: the classic footgun that bakes an API key into your public JavaScript.

Your whole stack, one view

Stripe, GitHub, Vercel, your database, your email — see healthy / degraded / down at a glance, grouped by project.

Checks you trigger

Status checks run only when you ask, straight from your machine to your providers. Nothing polls in the background, nothing phones home.

Keys encrypted on-device

Every API key is AES-256-GCM encrypted on your own machine. The UI only ever shows the last 4 characters.

Add any custom service

Not in the built-in catalog? Add a custom endpoint with your own auth header and Ms. Vibecode will watch it too.

Ms. Vibecode's environment-variable check: after you pick a framework, it flags any secret wearing a browser-exposed prefix that would leak into your public bundle, and suggests browser-safe names for keys like ANTHROPIC_API_KEY and GITHUB_TOKEN.

Private by design

Your keys are your business

Ms. Vibecode is built so your secrets physically can't leak through us — there's no "us" in the data path.

Encrypted at rest

Keys are AES-256-GCM encrypted. The encryption key lives in your OS keychain — never in the database, never in a .env file.

Loopback only

The local API binds to 127.0.0.1 on a random port. Nothing is reachable from off your machine — not even your own network.

No cloud, no signup

No account to create, no server holding your data. The only outbound calls are your status checks and a license check.

How it works

Up and running in three steps

Download & open

Install the app and open it. No account, no setup wizard — you land straight in Mission Control.

Add your projects & keys

Create a project for each app you've shipped, then paste in the API keys for the providers it uses. They're encrypted the moment you save.

Check the vitals

Hit check and Ms. Vibecode pings each provider and reports back — healthy, degraded, or down, with the last error if there is one.

Cutting-edge visualization technology

Your whole stack, rendered as a tiny town

Most tools would hand you another table of green dots. Ms. Vibecode has a totally high-tech graphical visualizer: hit Visualize and your project becomes a little town — one building per service, each with its own tiny worker. Healthy services stay busy and their workers wave; when something breaks, that worker downs tools and the lights go out. And the weather tells the story: clear skies when your stack is healthy, but the moment a critical service goes down, a storm rolls in over the town — with the culprit called out by name. You'll spot trouble at a glance — and yes, we spent a suspicious amount of time on the trees.

The Ms. Vibecode visualizer with every service healthy: connected services drawn as buildings in a sunny little town under clear skies, a worker busy at each plot.
Every service healthy — clear skies over the town.
The same town when a critical service goes down: a dark rainstorm rolls over it, the failing service marked red with its worker slumped, and a caption naming the culprit — 'Storm over your town — Supabase is down.'
A critical service down — a storm rolls in, culprit named.

Works with what you already use

24 providers built in

StripeGitHubVercel SupabaseNetlifyRender NeonPlanetScaleFirebase AppwriteRailwayFly.io ResendSendGridPostmark ClerkOpenAIClaude GeminiLemon SqueezyPaddle SquarespaceWebflowFramer

…plus any custom service you add with its own endpoint and auth header.

Pricing

Try it free, then own it

Start with a full-featured 14-day trial. When you're ready, a single license unlocks the app for good.

Free trial

$0 / 14 days

Every feature, no card, no signup.

  • Unlimited projects & services
  • All 24 built-in providers
  • Custom services
Download & start trial

FAQ

Questions, answered

Do my API keys ever leave my computer?

No. Keys are encrypted on your machine with AES-256-GCM and stored in a local database. The only outbound traffic is the status checks you trigger (which go straight to your providers) and a license validation call. There's no Ms. Vibecode server holding your data.

Is there a cloud account or signup?

None. You download the app and open it — that's it. There's a single local user: whoever is at the keyboard.

What does a status check actually do?

When you click check, the app makes an authenticated request from your machine to that provider's API and reports whether it's healthy, degraded, or down — including the last error message if something's wrong.

How does the security audit work?

It reuses the credentials you already connected and runs read-only checks for the misconfigurations that actually breach vibe-coded apps. For Supabase it fetches your project's public key and actually tries to read each table with it — so it catches Row Level Security left off and permissive policies that a config-flag check misses. It also flags anonymous write policies, scans your deployed site for secrets in the bundle, and checks headers and key hygiene. Nothing is ever written to your stack, and no data leaves your machine.

Is a clean audit a guarantee my app is secure?

No — and Ms. Vibecode will never claim it is. A clean run means no known misconfigurations were found. It isn't a penetration test and doesn't audit your application logic. Every finding comes with the evidence and a one-line fix, and when a check can't run, it says so instead of showing a false pass.

What's the "service town" visualizer?

It's a picture of your project instead of a list. Each connected provider becomes a themed building — a server rack for hosting, a data-cylinder stack for your database, a shop for payments, a post office for email — with data flowing along paths between them. Colour and motion show health: healthy services are lit and busy, anything down goes still and dark. It's the fastest way to understand a whole stack at a glance, especially if the underlying services are new to you.

Can it stop me leaking a secret?

That's one of the things it's best at. Tell Ms. Vibecode your framework — Vite, Next.js, Astro or SvelteKit — and it names each service's env vars with the right browser-safe prefix, and loudly flags any secret carrying a public prefix like VITE_ or NEXT_PUBLIC_. That's the mistake that bakes an API key into your public JavaScript, where anyone can read it — caught before you deploy instead of after.

Which platforms are supported?

macOS and Windows. The app is the same local-first design on every platform — your keys are encrypted on-device either way.

What happens when my trial ends?

The app prompts for a license key. Enter one and it unlocks for good and keeps working offline after activation. Your projects and keys are untouched the whole time.

Can I add a service that isn't built in?

Yes. Add a custom service with its own check endpoint and auth header, and Ms. Vibecode will track it alongside the 24 built-in providers.

Does it work for internal tools — a CRM or dashboard I built for myself?

Yes. An internal tool deployed to Supabase and Vercel runs on the same public infrastructure as any other app, so every check applies — most importantly, it uses the public key that ships in the tool's frontend to actually try to read your tables, which is exactly how "nobody knows the URL" internal tools get breached. The one boundary: a tool that's genuinely air-gapped — localhost, VPN, or corporate SSO, never publicly deployed — is out of reach for a remote check, and is mostly already protected by that isolation.