Check the packages your AI added for known holes.

Assistants add a package for every problem and pin the version they remember from training. Some of those versions have published vulnerabilities.

npx @neuralaxis/vibedoctor scan

What it looks like

It compiles. It ships. It’s wrong.

“npm install succeeded” says nothing about whether a version has a known exploit.

Unused packages still ship, still run install scripts, and still show up in advisories.

website/package-lock.json
"astro": "5.18.2"   → advisory fixed in 6.3.3

Example: A real finding on this website's own lockfile during its build.

What VibeDoctor reports

A ranked finding with the exact location.

  • npm, pnpm, Yarn, and Python lockfiles, through osv-scanner. VibeDoctor can download a pinned copy.
  • Dev-only and transitive dependencies are ranked below runtime ones.
FindingSeverityEvidenceFrom
Advisory ID (for example GHSA-…)
package@version, whether it is a runtime, dev, or transitive dependency, and the version that fixes it.
by advisory verified osv-scanner
Unused dependency
knip for JavaScript and TypeScript. deptry reports unused and missing packages in Python.
low–medium observed knip / deptry

Evidence grades say how sure the finding is. What verified, observed and heuristic mean →

How to fix it

  1. Upgrade to the fixed version and run your tests.
  2. If no fix exists, check whether you use the vulnerable code path, or replace the package.
  3. Remove packages nothing imports.

What this check can’t see

  • Known vulnerabilities only. A package with no published advisory looks clean.
  • It needs a lockfile, and the vulnerability lookup uses the network.

Fixing it, and the limits of this check

Run it

Check your repo now.

npx @neuralaxis/vibedoctor scan

Runs locally on JavaScript, TypeScript and Python repos. Hand the result to Cursor, Claude Code, Codex or Copilot with agent-plan. Agent setup →