<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Vibe Coding</title><link>https://vibecoding.rest/tags/security/</link><description>Recent content in Security on Vibe Coding</description><generator>Hugo</generator><language>en</language><atom:link href="https://vibecoding.rest/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>FFUF Web Fuzzing</title><link>https://vibecoding.rest/skills/ffuf-web-fuzzing/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/skills/ffuf-web-fuzzing/</guid><description>&lt;p&gt;This skill integrates the ffuf web fuzzer, letting Claude run authenticated fuzzing scans, auto-calibrate for noisy responses, and analyze results for real vulnerabilities during a penetration test.&lt;/p&gt;&#10;&lt;h2 id="why-a-skill-for-this"&gt;Why a skill for this&lt;/h2&gt;&#10;&lt;p&gt;Fuzzing tools have enough flags and calibration nuance that getting authenticated, low-noise scans right by hand takes real fuzzer expertise. Packaging that expertise as a skill makes competent fuzzing runs repeatable for anyone using it.&lt;/p&gt;</description></item><item><title>Threat Hunting with Sigma Rules</title><link>https://vibecoding.rest/skills/threat-hunting-sigma/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/skills/threat-hunting-sigma/</guid><description>&lt;p&gt;This skill uses Sigma detection rules — a vendor-neutral format for describing log-based threat signatures — to hunt for suspicious activity and analyze security events.&lt;/p&gt;&#10;&lt;h2 id="why-a-skill-for-this"&gt;Why a skill for this&lt;/h2&gt;&#10;&lt;p&gt;Sigma&amp;rsquo;s rule format is expressive but verbose to write and match by hand across large event logs. A skill that already knows the format turns threat hunting into a repeatable query task instead of a manual log-reading exercise.&lt;/p&gt;</description></item><item><title>Trail of Bits Security Skills</title><link>https://vibecoding.rest/skills/trail-of-bits-security/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/skills/trail-of-bits-security/</guid><description>&lt;p&gt;Trail of Bits&amp;rsquo; security skills bring their own audit tooling — static analysis with CodeQL and Semgrep, variant analysis, and vulnerability pattern detection — into Claude Code.&lt;/p&gt;&#10;&lt;h2 id="why-a-skill-for-this"&gt;Why a skill for this&lt;/h2&gt;&#10;&lt;p&gt;Security auditing firms encode years of hard-won pattern knowledge into their tooling configs. Packaging that as a skill means Claude Code inherits Trail of Bits&amp;rsquo; actual audit methodology instead of a generic security pass.&lt;/p&gt;</description></item><item><title>Security Best Practices Skill</title><link>https://vibecoding.rest/skills/security-best-practices-skill/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/skills/security-best-practices-skill/</guid><description>&lt;p&gt;This curated Codex skill applies a secure-coding checklist during code generation and review, catching common vulnerability classes as code is written.&lt;/p&gt;&#10;&lt;h2 id="why-a-skill-for-this"&gt;Why a skill for this&lt;/h2&gt;&#10;&lt;p&gt;Security issues are cheaper to prevent during generation than to catch in a later review pass. Baking a checklist into the generation step catches classes of bugs before they&amp;rsquo;re ever committed.&lt;/p&gt;</description></item><item><title>Security Threat Model Skill</title><link>https://vibecoding.rest/skills/security-threat-model-skill/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/skills/security-threat-model-skill/</guid><description>&lt;p&gt;This curated Codex skill walks through producing a structured threat model for a system — assets, trust boundaries, and attack surfaces — rather than an ad hoc security discussion.&lt;/p&gt;&#10;&lt;h2 id="why-a-skill-for-this"&gt;Why a skill for this&lt;/h2&gt;&#10;&lt;p&gt;Threat modeling is only useful if it&amp;rsquo;s structured and complete; an unstructured conversation tends to miss entire categories of risk. A skill that enforces the methodology produces a threat model that&amp;rsquo;s actually useful to a security reviewer.&lt;/p&gt;</description></item><item><title>Codacy</title><link>https://vibecoding.rest/tools/codacy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/tools/codacy/</guid><description>&lt;p&gt;Codacy runs static analysis, security scanning, and coverage checks on every commit and pull request, surfacing issues as a quality score and letting teams enforce consistent standards across large codebases.&lt;/p&gt;</description></item><item><title>Sonar</title><link>https://vibecoding.rest/tools/sonar/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vibecoding.rest/tools/sonar/</guid><description>&lt;p&gt;Sonar has scanned code for bugs, vulnerabilities, and code smells since SonarQube&amp;rsquo;s early days, and now extends that static analysis foundation with AI Code Assurance and AI-powered review features that specifically check AI-generated code against the same quality gates used for human-written code.&lt;/p&gt;</description></item></channel></rss>