lexvibe
v0.1.0
Published
LexVibe CLI — 100% local legal compliance scan for vibe-coded apps: detects analytics, payments, AI and third parties in your project and tells you which legal documents you need. Your code never leaves your machine.
Maintainers
Readme
lexvibe
100% local legal compliance scan for vibe-coded apps. One command, zero uploads:
npx lexvibeScans the current directory (or npx lexvibe path/to/project) and tells you:
- What your app actually processes — analytics, payments, generative AI, email collection, third-party services — detected from your dependencies, source code and mobile manifests (
Info.plist,AndroidManifest.xml,Podfile,build.gradle,app.json). - Which platforms it targets (web / iOS / Android) and which languages it supports.
- Which legal documents and obligations that implies: privacy policy, terms, cookie consent, sales terms, EU AI Act transparency notice, Apple App Privacy / Google Play Data Safety, App Tracking Transparency.
Privacy
The scan runs entirely on your machine. No network calls, no telemetry, nothing is uploaded — this is the trust-preserving path for private repos. The detection engine is open source at marcosnovo/lexvibe-mcp (the same one used by the LexVibe MCP server), and you can inspect exactly what this CLI runs in the published package: npm view lexvibe / npmjs.com/package/lexvibe.
Options
| Flag | Effect |
| ----------- | ---------------------------------------------- |
| --json | Machine-readable output (full scan + findings) |
| --version | Print version |
| --help | Show help |
Fixing what it finds
LexVibe generates and hosts the documents (privacy policy, terms, cookie banner with real script blocking, EU AI Act notice) in 12 languages, auto-updated when regulations change: golexvibe.com/activate. There's also a free online checker at golexvibe.com/check and an MCP server for Claude Code / Cursor.
Not legal advice
The scan is indicative, based on what is detectable in your project. It is not legal advice.
