
slopsec
A Claude Code skill that security-audits vibe-coded SaaS apps. 50 common ways AI-generated apps get pwned, turned into a repeatable checklist, severity scori…
Install with your AI
Paste into Claude Code, Cursor, or any agent — it reads the repo and wires the tool into your project.
Install and set up slopsec (claude-plugin project) into my current project. Found on https://claudeers.com/slopsec Repo: https://github.com/lachydotmcg/slopsec Homepage/docs: — Detected install method: claude-plugin → /plugin install slopsec@lachydotmcg/slopsec Category: security. Platforms: api. Read the repo's README for exact setup and env vars, then install it and wire it into my project. Claudeers Health Verdict: active; community-verified: false. Confirm the source before running anything.
/plugin marketplace add lachydotmcg/slopsec /plugin install slopsec@lachydotmcg/slopsec
git clone https://github.com/lachydotmcg/slopsec
// compatibility
| Platforms | api |
|---|---|
| Operating systems | — |
| AI compatibility | claude |
| License | MIT |
| Pricing | open-source |
| Language | — |
slopsec
Did you just get a unforeseen $200 bill from AWS? Stop 'hiding' your API keys in plaintext. It sounds like you need: A Claude Code skill that security-audits your vibe-coded SaaS apps, so your slop isn't just slop, its secure slop!
Bots scan the whole internet constantly. The premise here is a real one; freshly launched apps can get probed by an attacker within 3 hours of going live, with this it ensures that your AI Agent isn't skipping the security checks that count.
slopsec turns 50 recurring ways vibe-coded apps get pwned into a repeatable audit; scope the app, walk the checklist, prove the findings, prioritize by severity, fix, and re-verify!
Just run /slopsec for slopsec to save the day! (and your wallet)
What's inside
| File | Purpose |
|---|---|
SKILL.md | The skill — how to run an audit, the non-negotiables, categories |
references/principles.md | All 50 principles, grouped, with "what to look for" + "how to fix" |
references/checklist.md | Tick-box audit you walk top to bottom |
references/severity.md | P0–P3 scoring so the catastrophic stuff leads |
references/report-template.md | Findings report format |
Install
As a plugin (easiest, and you get updates):
/plugin marketplace add lachydotmcg/slopsec
/plugin install slopsec@slopsec
/reload-plugins
Run it with /slopsec:slopsec (plugin skills get namespaced, sorry). Later,
pull updates with /plugin marketplace update.
Or drop the folder in manually:
- Project:
.claude/skills/slopsec/ - Personal:
~/.claude/skills/slopsec/
Either way, you can also just ask Claude "run a security review before I launch" or "is my app secure?" and the skill triggers on its own.
The 9 categories
- Secrets & exposure · 2. AuthN & AuthZ · 3. Database & storage · 4. Injection & input · 5. Sessions, tokens & cookies · 6. Frontend trust boundary · 7. Rate limiting & exposure surface · 8. AI-specific · 9. Ops, logging & dependencies
Scope & ethics
For defensive hardening and authorized review only. Audit apps you own or have explicit permission to test. Don't probe other people's apps.
Credit
The 50 principles are adapted from a widely-shared list of common vibe-coded app vulnerabilities. Skill structure and audit workflow are original.
License
MIT
// faq
What is slopsec?
A Claude Code skill that security-audits vibe-coded SaaS apps. 50 common ways AI-generated apps get pwned, turned into a repeatable checklist, severity scoring, and findings report!. It is open-source on GitHub.
Is slopsec free to use?
slopsec is open-source under the MIT license, so it is free to use.
What category does slopsec belong to?
slopsec is listed under security in the Claudeers registry of Claude-compatible tools.
// embed badge
[](https://claudeers.com/slopsec)
// retro hit counter
[](https://claudeers.com/slopsec)
// reviews
// guestbook
// related in Security & Compliance
A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy injectors to reality checkers. Each agent is a specia…
π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video.
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
🐶 A curated list of Web Security materials and resources.