Vibe coding, building apps mostly by prompting an AI and accepting what works, has made it possible to ship a product in a weekend. It has also produced a wave of insecure apps.

Security researchers who scanned large numbers of AI-built production apps found a majority had security issues, many with critical ones, including hundreds of exposed secrets. Independent testing of AI-generated code has also found a large share introduces common OWASP Top 10 weaknesses.

The problems are predictable, which means a checklist catches most of them.

Authentication and authorisation

  • Every API route checks that the user is logged in.
  • Every data access checks that the user owns or may access that record, not just that they are logged in.
  • Admin actions are protected on the server, not only hidden in the UI.
  • If you use a hosted database with row-level security, it is enabled on every table and the policies are tested.
sql
-- Supabase / Postgres example: users only see their own rows
alter table notes enable row level security;
create policy "own notes" on notes for select using (auth.uid() = user_id);

Secrets

  • No API keys in frontend code or public environment variables (PUBLIC_, NEXT_PUBLIC_, VITE_).
  • Secret keys only used from server code.
  • Repository history scanned for leaked keys.

Input handling

  • Database queries use parameters or an ORM, never string concatenation.
  • User content is escaped before rendering as HTML.
  • File uploads check type and size, and are stored outside the web root.
  • Any "fetch this URL" feature blocks internal addresses (SSRF).

Web basics

  • HTTPS everywhere.
  • Security headers set: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy.
  • Cookies are HttpOnly, Secure and SameSite.
  • CSRF protection on state-changing forms that rely on cookies.
  • CORS allows only your own origins, never * with credentials.

Abuse and cost

  • Rate limits on login, sign-up, password reset and any endpoint that calls a paid AI API.
  • Spending limits and alerts on AI and cloud accounts.

Dependencies and errors

  • Dependencies are real, maintained packages (check for look-alike names).
  • Production error pages do not show stack traces or environment details.

Ask the AI to attack its own code

After building a feature, ask your assistant to review it as a security tester: "List ways a malicious user could access other users' data through this code." It will not catch everything, but it catches the obvious.

Key takeaways

  • Authorisation on every data access is the most common gap.
  • Keep secrets on the server and out of public env variables.
  • Set security headers, rate limits and spending alerts before launch.
  • Treat AI-generated code as untrusted until reviewed.