Did you just get a unforeseen $200 bill from AWS? Stop 'hiding' your API keys in plaintext. It sounds like you need: A Claude Code skill that security-audits your vibe-coded SaaS apps, so your slop isn't just slop, its secure slop!
Bots scan the whole internet constantly. The premise here is a real one; freshly launched apps can get probed by an attacker within 3 hours of going live, with this it ensures that your AI Agent isn't skipping the security checks that count.
slopsec turns 50 recurring ways vibe-coded apps get pwned into a repeatable audit; scope the app, walk the checklist, prove the findings, prioritize by severity, fix, and re-verify!
Just run /slopsec for slopsec to save the day! (and your wallet)
| File | Purpose |
|---|---|
SKILL.md | The skill — how to run an audit, the non-negotiables, categories |
references/principles.md | All 50 principles, grouped, with "what to look for" + "how to fix" |
references/checklist.md | Tick-box audit you walk top to bottom |
references/severity.md | P0–P3 scoring so the catastrophic stuff leads |
references/report-template.md | Findings report format |
As a plugin (easiest, and you get updates):
/plugin marketplace add lachydotmcg/slopsec
/plugin install slopsec@slopsec
/reload-plugins
Run it with /slopsec:slopsec (plugin skills get namespaced, sorry). Later,
pull updates with /plugin marketplace update.
Or drop the folder in manually:
.claude/skills/slopsec/~/.claude/skills/slopsec/Either way, you can also just ask Claude "run a security review before I launch" or "is my app secure?" and the skill triggers on its own.
For defensive hardening and authorized review only. Audit apps you own or have explicit permission to test. Don't probe other people's apps.
The 50 principles are adapted from a widely-shared list of common vibe-coded app vulnerabilities. Skill structure and audit workflow are original.
MIT
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
npx claudepluginhub lachydotmcg/slopsec --plugin slopsecHarness-native ECC plugin for engineering teams - 67 agents, 279 skills, 94 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Binary reverse engineering, malware analysis, firmware security, and software protection research for authorized security research, CTF competitions, and defensive security
Next.js development expertise with skills for App Router, Server Components, Route Handlers, Server Actions, and authentication patterns
Comprehensive .NET development skills for modern C#, ASP.NET, MAUI, Blazor, Aspire, EF Core, Native AOT, testing, security, performance optimization, CI/CD, and cloud-native applications
817 cybersecurity skills covering web security, pentesting, DFIR, threat intelligence, cloud security, malware analysis, and more.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claim