about our scanner
Saw us in your logs?
Here's what that was.
Requests with this User-Agent come from VibeProtect, a security checker for apps built with AI builders. It only scans apps whose owners have proved to us that they control them.
User-Agent: VibeProtect-Scanner/1.0 (+https://vibeprotect.dev/scanner)
Who it scans
Only apps that an account holder has verified, at that exact address. Verification means
publishing a token we generate: a file at /.well-known/vibeprotect.txt, a
vibeprotect-verification meta tag on the home page, or a DNS TXT record on a
custom domain. We re-check every proof nightly and stop scanning any app whose proof has
gone. More on verification.
If the app is yours and you did not set this up, someone with access to your app (a teammate, a contractor) published a token. Remove the file or tag and scanning stops after the next nightly check, or email us and we will stop it now.
What it does
- Loads the app's home page and a handful of other pages, on that address and its www. twin only.
- Downloads the JavaScript those pages include, the same files every visitor's browser gets, and looks for secret keys in them.
- Reads the response headers and completes a TLS handshake to check the HTTPS setup.
- Fetches
/.well-known/vibeprotect.txtand the home page to re-check the owner's proof, every night.
what it never does
Read-only, always
No logins
It never signs in, signs up or guesses passwords. It sees what a visitor who is not logged in sees.
No writes
Only plain page and file requests. It never submits forms, creates, changes or deletes anything.
No attacks
No exploit payloads, no fuzzing, no load testing, no crawling beyond the verified address.
No backend probing
It does not connect to the databases or APIs your app uses. Database rules are checked in the code, through the GitHub App, if the owner connects it.
No secret values kept
Keys it finds are stored redacted, like sk-proj-Ab…9xQ: enough to say which key, never enough to use it. It never uses a key it finds.
No hiding
Every request carries the User-Agent above, which links here.
report abuse
Think we scanned something we shouldn't have?
Email security@vibeprotect.dev with the address that was scanned, roughly when, and a few log lines if you have them. A person reads it, and if the scan was not authorized we stop it and remove the app from the account that added it.
The same address is the place to report a security problem in VibeProtect itself. Thank you in advance.
VibeProtect is operated by Instant City Solutions LLC, Miami, Florida.