Skip to content
CAI
Software that uses CAICheck a score

automazeio/vibeproxy

52.9

Adequate · 30 September 2026

5.1k

lines of production code

Swift

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

VibeProxy is a macOS application that acts as a local proxy server for various AI model providers, including Claude, Gemini, and custom OpenAI-compatible services. It manages multiple authenticated accounts, handles credential storage, and routes requests through a configurable backend CLI with support for features like Vercel AI Gateway integration. The system includes auto-update capabilities, security hardening via loopback binding, and automated release packaging.

Features

Initial configuration file for CLIProxyAPI

The \src/Sources/Resources/config.yaml\ file has been added to define the default settings for the CLIProxyAPI server. This configuration sets the server to listen on port 8318 bound to localhost (127.0.0.1) for security, enables usage statistics, and configures a 10-minute request timeout suitable for extended thinking operations. It also includes settings for Amp CLI integration, retry logic, and OAuth-based authentication without requiring explicit API keys.

src/Sources/Resources · high confidence

Introduce multi-account support, custom provider configuration, and Vercel AI Gateway integration

The application now supports managing multiple authenticated accounts per service (Claude, Codex, Gemini, etc.) with the ability to enable or disable individual accounts, while automatically handling expired credentials. Users can also configure custom OpenAI-compatible providers via the settings UI, with credentials stored securely and validated against reserved provider names. Additionally, a toggle for Vercel AI Gateway integration allows routing Claude requests through an external gateway for enhanced access control, and the menu bar now includes a standard Edit menu with keyboard shortcuts (Cmd+C/V/X/A).

src/Sources · high confidence

New scripts for release packaging and backend flag parity checking

Added \scripts/create-release.sh\ to automate building the VibeProxy app bundle and generating a distributable ZIP with SHA-256 checksums, and \scripts/check-backend-flag-parity.sh\ to verify that login flags required by the app (such as GitHub Copilot, Gemini, and Qwen logins) are supported by the backend CLI, gating unavailable features at runtime.

scripts · high confidence

Removals

Removal of macOS menu bar application components

The macOS menu bar application entry point (AppDelegate) and its associated core logic have been removed. This includes the deletion of the ServerManager (which handled starting/stopping the CLI proxy binary and managing logs), the AuthManager (which tracked authentication status for Claude and Codex services), and the SettingsView (the UI for server controls, launch-at-login, and service connections). Users will no longer have access to the menu bar interface for managing the proxy server or its authentication states.

Sources · high confidence

Behavioural changes

Rebrand to VibeProxy and enable Sparkle auto-updates

The application has been rebranded from ProxyBar to VibeProxy, reflected in the bundle identifier (com.vibeproxy.app), display name, and copyright holder (Automaze, Ltd.). The version has been updated to 1.5.0. Additionally, Sparkle auto-update support has been integrated, configuring the app to check for updates daily via a specific GitHub-hosted appcast, with automatic updates disabled but automatic checks enabled.

src · high confidence

VibeProxy rebrand, multi-provider support, and security hardening

The application has been rebranded from ProxyBar to VibeProxy, with the Makefile, README, and installation guides updated to reflect the new name and expanded capabilities. Users can now authenticate with additional providers including Gemini, Kimi, Qwen, Antigravity, and Z.AI GLM, and control model availability via a new Provider Priority toggle. Security and stability have improved: the proxy now binds to loopback (127.0.0.1) by default with an optional LAN setting, the main executable is signed with entitlements to fix the missing menu bar icon, and login buttons are gated by backend CLI capabilities to prevent raw errors. The Swift test suite now runs in CI, and the CHANGELOG documents these fixes alongside the rebrand.

(repo-wide) · high confidence

Test coverage

Added test coverage for backend capability detection, config merging, and credential stores

New tests in src/Tests verify that the app correctly detects backend CLI flags (distinguishing between Plus-era and stock CLIProxyAPI builds), maps authentication commands to their required backend flags, and merges user configuration with bundled defaults while preserving runtime-editable keys. Additional tests cover the config input fingerprinting logic (ensuring only config and managed credential files trigger rebuilds), the custom provider credential store (save, load, disable/reenable, concurrent access, and malformed file handling), the ZAI API key store, the model alias mapper (rewriting ghcp-op/son/haiku aliases), the ThinkingProxy loopback binding, and the provider wiring that connects service types to their specific authentication flows.

src/Tests · high confidence

Dependencies

Add Sparkle and Yams dependencies

The project now includes the Sparkle (v2.5.0+) and Yams (v5.1.3+) libraries as dependencies, enabling auto-update support and YAML configuration parsing. The package structure has also been reorganized with the manifest moved to src/ and a new test target added.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 54 → 53 (-1.2)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 83 → 81 (-2.3)
  • Architecture 100 → 100 (+0.0)
  • Maturity 46 → 47 (+1.3)
  • Readiness 56 → 57 (+1.4)
  • Security 48 → 46 (-1.7)

Resolved (1)

  • Documentation: no installation or build instructions (README.md)

New (29)

  • AccountRowView.body (cognitive 25) (src/Sources/SettingsView.swift)
  • AccountRowView.body (cyclomatic 17) (src/Sources/SettingsView.swift)
  • Coverage not measured — Swift suite
  • CustomProviderCredentialRowView.body (cognitive 21) (src/Sources/SettingsView.swift)
  • CustomProviderRow.body (cognitive 35) (src/Sources/SettingsView.swift)
  • CustomProviderRow.body (cyclomatic 18) (src/Sources/SettingsView.swift)
  • Duplicated block (10–12 lines × 2) (src/Sources/SettingsView.swift)
  • Duplicated block (11–12 lines × 2) (src/Sources/ServerManager.swift)
  • Duplicated block (12 lines × 2) (src/Sources/SettingsView.swift)
  • Duplicated block (16 lines × 2) (src/Sources/SettingsView.swift)
  • Duplicated block (18 lines × 2) (src/Sources/ServerManager.swift)
  • Duplicated block (18–19 lines × 2) (src/Sources/SettingsView.swift)
  • Duplicated block (25 lines × 2) (src/Sources/SettingsView.swift)
  • Duplicated block (4–6 lines × 8) (src/Sources/SettingsView.swift)
  • Duplicated block (6 lines × 4) (src/Sources/SettingsView.swift)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: src/Sources/ServerManager.swift (src/Sources/ServerManager.swift)
  • …and 9 more

Changes since last survey

  • 67 commits — 64 feature/other, 3 fixes

By area

  • (root) — 42 commits
  • src/Sources — 23 commits
  • .github/workflows — 1 commit
  • src/Tests — 1 commit

Notable commits

  • fix: fix: bind ThinkingProxy to loopback by default; sign main executable with entitlements (#565)
  • fix: fix: gate login flows on backend CLI capabilities (Copilot/Gemini/Qwen) + CI parity guard (#566)
  • fix: fix: point the in-app backend credit link at CLIProxyAPI (#573)
  • change: Bump CLIProxyAPI to 7.3.10 (#557)
  • change: Bump CLIProxyAPI to 7.3.11 (#558)
  • change: Bump CLIProxyAPI to 7.3.12 (#559)
  • change: Bump CLIProxyAPI to 7.3.14 (#560)
  • change: Bump CLIProxyAPI to 7.3.15 (#561)
  • change: Bump CLIProxyAPI to 7.3.16 (#562)
  • change: Bump CLIProxyAPI to 7.3.17 (#563)
  • change: Bump CLIProxyAPI to 7.3.18 (#567)
  • change: Bump CLIProxyAPI to 7.3.19 (#568)
  • change: Bump CLIProxyAPI to 7.3.3 (#550)
  • change: Bump CLIProxyAPI to 7.3.4 (#551)
  • change: Bump CLIProxyAPI to 7.3.5 (#552)
  • change: Bump CLIProxyAPI to 7.3.6 (#553)
  • change: Bump CLIProxyAPI to 7.3.7 (#554)
  • change: Bump CLIProxyAPI to 7.3.8 (#555)
  • change: Bump CLIProxyAPI to 7.3.9 (#556)
  • change: Bump CLIProxyAPI to 8.0.1 (#569)
  • …and 47 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

automazeio/vibeproxy was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f88df7da38593cf7014ccbb88f0f1820c318d439 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.