A security audit crew for vibe-coded apps — 48 plain-English checks delivered as Claude Code skills
Lictor is the bodyguard vibe-coded apps didn't ship with. It's an open-source (Apache-2.0) skill suite that installs into Claude Code as a plugin and gives you four slash commands: /lictor-security-check runs a 48-check audit mapped to the OWASP Top 10 for Web, API, Mobile, and LLM apps plus the CWE Top 25; /lictor-explain translates any finding into plain English; /lictor-fix-it applies fixes with your approval; and /lictor-rotate walks a leaked key through rotation. Everything runs 100% locally — no token, no signup, no telemetry — and every check is a Markdown file you can read before it runs.
The audit is performed by a crew of eleven named specialist agents — Wolf the orchestrator, Hawk the pattern scout hunting the bug shapes vibe-coders ship most (RLS gaps, env-var leaks, unsigned webhooks), Lyrebird the voice keeper rewriting findings as "your X does Y, anyone can do Z" — with a measured benchmark so the accuracy claims are verifiable. On top of the free suite, Lictor Patrol scans the public internet for AI-built apps leaking live keys (3,700+ critical and high-severity findings surfaced, none ever exploited, disclosed ethically), and a hosted business plan starts at $49/mo.
The meta story: Lictor itself was "Built in 30 days by one person and an 11-agent crew," per its launch announcement — a 20-year security engineer who got tired of watching Lovable/Bolt/v0 apps leak Firebase keys on day one, paired with Claude. The GitHub repo (Raffa-jarrl/Lictor-AI, 18 stars) states it plainly in its README: "Built by a 20-year security engineer + Claude."