Provider hosted
No sign in
Tools: 1

VibeScan

VibeScan

Free Chrome extension that scans your vibe-coded app for exposed databases and leaked secrets. Find out in 10 seconds.

https://vibescan.online/

Use in your AI tool

Use the tools from this page

Opens ChatGPT on the web or desktop and asks it to use the WebMCP tools available here.

Connect the MCP server

Connect straight to this server’s public endpoint.

Remote MCP URL
https://vibescan.online/mcp

Use on MCPBundles

We add this server to your workspace, then open Studio — saved access, one connection to many servers, with a history of what ran.

Last probed Sep 14, 2026 · vibescan.online

1tool discovered

Tools discovered (1)

  • Scan an app for security exposures

    Run a VibeScan security scan on a deployed web app you own. Checks for a publicly readable database (missing Supabase RLS / open Firebase), leaked API secrets in the frontend bundle, exposed config (.env, .git, source maps), and missing security headers. Read-only; uses only the public access the app already ships. Args: - url (string): the deployed app's URL to scan, e.g. https://myapp.com (must be a public http(s) app you own or control). Returns: a grade (A–F), score (0–100), issue counts

Get your MCP into directories

A working endpoint is step one. Directory coverage is the coordinated launch across ChatGPT, Claude, Cursor, the MCP Registry, and community indexes.

Directory coverage for brands

Frequently Asked Questions

What is the VibeScan MCP server?

Free Chrome extension that scans your vibe-coded app for exposed databases and leaked secrets. Find out in 10 seconds.

How do I connect VibeScan to my AI agent?

Use the MCP endpoint listed on this page in your MCP client configuration. One-click install pills support Claude, Cursor, VS Code, and other hosts. Copy the remote MCP URL if your client needs a manual entry.

How many tools does VibeScan provide?

MCPBundles probed 1 tool on the live server. The tool list on this page reflects what was discovered at the last refresh — connect your client to see the full set available to your session.

What authentication does VibeScan require?

No provider sign-in was required during MCPBundles' probe. Your client may still need MCPBundles credentials depending on how you connect.

Maintain this listing

Operate VibeScan? Verify ownership to take over this directory entry.

Operate VibeScan?

This server appears in the MCPBundles directory. Verify you operate it to take over the listing — name, description, logo, contact email, and skill content. We email a 6-digit code to a maintainer address your server publishes in /.well-known/security.txt or /.well-known/mcpbundles.json. Free, takes about a minute.

Claim this listing