By lachydotmcg
Security audit and hardening for vibe-coded SaaS apps. Walks the 50 most common ways AI-generated apps get owned and produces a prioritized fix list.
Did you just get a unforeseen $200 bill from AWS? Stop 'hiding' your API keys in plaintext. It sounds like you need: A Claude Code skill that security-audits your vibe-coded SaaS apps, so your slop isn't just slop, its secure slop!
Bots scan the whole internet constantly. The premise here is a real one; freshly launched apps can get probed by an attacker within 3 hours of going live, with this it ensures that your AI Agent isn't skipping the security checks that count.
slopsec turns 50 recurring ways vibe-coded apps get pwned into a repeatable audit; scope the app, walk the checklist, prove the findings, prioritize by severity, fix, and re-verify!
Just run /slopsec for slopsec to save the day! (and your wallet)
| File | Purpose |
|---|---|
SKILL.md | The skill — how to run an audit, the non-negotiables, categories |
references/principles.md | All 50 principles, grouped, with "what to look for" + "how to fix" |
references/checklist.md | Tick-box audit you walk top to bottom |
references/severity.md | P0–P3 scoring so the catastrophic stuff leads |
references/report-template.md | Findings report format |
As a plugin (easiest, and you get updates):
/plugin marketplace add lachydotmcg/slopsec
/plugin install slopsec@slopsec
/reload-plugins
Run it with /slopsec:slopsec (plugin skills get namespaced, sorry). Later,
pull updates with /plugin marketplace update.
Or drop the folder in manually:
.claude/skills/slopsec/~/.claude/skills/slopsec/Either way, you can also just ask Claude "run a security review before I launch" or "is my app secure?" and the skill triggers on its own.
For defensive hardening and authorized review only. Audit apps you own or have explicit permission to test. Don't probe other people's apps.
The 50 principles are adapted from a widely-shared list of common vibe-coded app vulnerabilities. Skill structure and audit workflow are original.
MIT
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimnpx claudepluginhub lachydotmcg/slopsec --plugin slopsecBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Pre-deploy security audit for vibe-coded apps. Catches unauthenticated admin APIs, missing RLS, leaked service keys, exposed debug routes.
Agentic-Security is a powerful Claude Code plugin that automatically performs Application Security Testing (SAST, SCA, secrets detection, and more). Think of it as the easy button for making your Claude-generated code safe and secure.
Perform security audit on codebase
Automated OWASP security checks — Web Top 10:2025, LLM Top 10:2025, API Security Top 10:2023
Perform security audit on codebase
AI-powered security auditing with interactive skills, automated agents, web dependency scanning, and supply chain hardening for comprehensive vulnerability detection and reporting