Back to products
VibeShift MCP

VibeShift MCP

Get secure, working code in 1 shot

Overview

What it is

Put cursor in auto feedback loop so that it tries to generate secure, fully working code in one shot. Completely open source.

Intent

I need it when

Embed security validation into AI-assisted development workflows to shift security left

VibeShift creates a feedback loop where AI-generated code is automatically scanned, vulnerabilities are reported with evidence and suggestions, and the AI assistant can propose or apply fixes, enabling rapid security-aware development cycles.

Run regression tests reliably to catch security regressions and functionality breaks

VibeShift executes recorded JSON test files using Playwright, performs visual regression testing with pixelmatch and vision LLM approaches, and returns detailed execution results with failures and evidence paths for debugging.

Discover potential security test cases and coverage gaps across web applications

VibeShift crawls websites using BrowserController and LLM analysis to suggest test steps for discovered pages, helping teams identify untested flows and potential security gaps in their applications.

Record and execute automated test flows for web applications without manual test script writing

VibeShift records Playwright-based test scripts from natural language descriptions, executes them deterministically, captures screenshots and console logs, and enables self-healing tests that adapt to code changes automatically.

Automatically detect security vulnerabilities in AI-generated code before it reaches production

VibeShift integrates with AI coding assistants (Cursor, GitHub Copilot, Claude Code) via MCP to perform automated SAST analysis, identify vulnerabilities like XSS and SQL injection, and provide detailed remediation feedback directly to the AI assistant for immediate fixes.

Drop

Not a fit when

  • User needs commercial support or SLA guarantees for production security scanning
  • Organization requires proprietary, closed-source security tools with vendor accountability
  • Team lacks Python 3.10+ environment or cannot install MCP and Playwright dependencies
  • User needs real-time security scanning without manual MCP server setup and configuration
  • Organization uses non-MCP-compatible AI coding assistants or legacy development workflows
Commercials

Pricing

Free, open-source