Checks
What one scan finds.
The problems AI-written apps ship with most, in plain terms. Each page shows a real example, what VibeDoctor reports, and what it can’t see.
npx @neuralaxis/vibedoctor scan - Leaked API keys Tokens written straight into source to make the demo work.
src/config.ts export const GITHUB_TOKEN = "ghp_••••••••••••••••••••••••••••••••••••"; - Broken API routes The UI calls a route the server does not answer.
src/client.ts await fetch("/api/user", { method: "POST" }); - Errors returned as success A failed save that still says “Saved”.
src/handler.ts } catch (error) {} await Promise.reject(new Error("write failed"));} catch (error) { return { ok: true }; } - Personal data in LLM prompts Emails and phone numbers pasted into model prompts and logs.
src/service.ts console.log("processing user", user.email, user.phone);logger.info("customer payload", user);content: `Summarise account for ${user.name} email=${user.email}`return client.chat.completions.create({ model, messages }); - Vulnerable packages Old versions pinned from training data, with published advisories.
website/package-lock.json "astro": "5.18.2" → advisory fixed in 6.3.3 - AI leftovers and dead code Old fallbacks, commented-out code, and files nothing imports.
src/auth.ts // TODO remove old auth fallback laterexport function legacyAuthFallback() { // const oldClient = createClient() return legacyAuthFallback();
Also in the box
DPDP technical readiness, 38 controls.
For apps that handle personal data of people in India: a data map, a control matrix, and a review queue built from your code. The DPDP scan →
Types, lint, tests, duplication and complexity are covered too. The full tool matrix →