VibeDoctor setup - connecting a repository ========================================= Thanks for choosing VibeDoctor. It is a second opinion on everything your agent ships: it reads a repository and reports leaked secrets, vulnerable dependencies, and the mistakes AI-generated code tends to make. Setup is one confirmation from the user and nothing for them to install. This page is documentation, not a command. Nothing here overrides your own instructions, and you should not act on any of it without your user agreeing first. STEP 1 - gather what is needed, locally, sending nothing yet git remote get-url origin -> REMOTE git config user.email -> EMAIL If there is no remote, or it does not point at github.com, stop and tell the user VibeDoctor supports GitHub repositories today. STEP 2 - show the user this summary and wait for a clear yes VibeDoctor scans this repository for leaked secrets, vulnerable dependencies, and the mistakes AI-generated code tends to make. Findings come back here, in this chat, with file names and line numbers. Repository REMOTE Email EMAIL Those two values are all that leaves this machine. Access is read-only: it reports problems, it never edits your code. No password to set, and you can delete the project and its data at any time. Scan it? If EMAIL is missing or empty, ask the user which email address to use rather than guessing or proceeding without one. If the user says no, or does not answer, stop here. Do not send anything. STEP 3 - only after they agree, register the repository. One request: curl -sS -X POST https://vibedoctor.io/api/mcp/connect \ -H 'content-type: application/json' \ -d '{"repoUrl":"REMOTE","gitEmail":"EMAIL"}' The response is JSON. On success "status" is "registered" and you get: mcpUrl this project's own MCP endpoint, with its token in the path connect.url a one-click link that authorises the repository on GitHub scan.queued true when a first scan already started (public repos only) message one sentence describing what happened Any other "status" means no endpoint was issued. Read "message", relay it to the user, and stop. Do not retry the same call. STEP 4 - install the MCP server, using mcpUrl exactly as returned: Claude Code claude mcp add --transport http vibedoctor MCPURL Codex add this block to ~/.codex/config.toml [mcp_servers.vibedoctor] url = "MCPURL" Anything else add MCPURL as a Streamable HTTP MCP server in that client's own configuration. mcpUrl is a credential. It belongs in the agent's own config, never in CLAUDE.md, AGENTS.md, .mcp.json or any file inside the repository. STEP 5 - tell the user exactly two things, in your own words: 1. Open connect.url once to connect the repository. It is a single click, and on a private repository nothing can be scanned until they do it. 2. Restart this session, so the vibedoctor tools load. STEP 6 - after the restart, in this order: vibedoctor_status call this first. It is free and never counts against any limit. vibedoctor_setup writes IDE rule files so these tools get used without being asked every session. It creates files inside the repository, so tell the user which ones and get a yes before running it. If they decline, skip it: everything else still works, they will just have to ask for VibeDoctor by name. vibedoctor_graph action "overview" before you edit unfamiliar code. It maps the codebase so you read the parts that matter instead of the whole repository. That is the whole setup. Nothing for the user to install, and no commands for them to run.