Vibe coding, building apps mostly by prompting an AI and accepting what works, has made it possible to ship a product in a weekend. It has also produced a wave of insecure apps.
Security researchers who scanned large numbers of AI-built production apps found a majority had security issues, many with critical ones, including hundreds of exposed secrets. Independent testing of AI-generated code has also found a large share introduces common OWASP Top 10 weaknesses.
The problems are predictable, which means a checklist catches most of them.
Authentication and authorisation
- Every API route checks that the user is logged in.
- Every data access checks that the user owns or may access that record, not just that they are logged in.
- Admin actions are protected on the server, not only hidden in the UI.
- If you use a hosted database with row-level security, it is enabled on every table and the policies are tested.
-- Supabase / Postgres example: users only see their own rows
alter table notes enable row level security;
create policy "own notes" on notes for select using (auth.uid() = user_id);Secrets
- No API keys in frontend code or public environment variables (
PUBLIC_,NEXT_PUBLIC_,VITE_). - Secret keys only used from server code.
- Repository history scanned for leaked keys.
Input handling
- Database queries use parameters or an ORM, never string concatenation.
- User content is escaped before rendering as HTML.
- File uploads check type and size, and are stored outside the web root.
- Any "fetch this URL" feature blocks internal addresses (SSRF).
Web basics
- HTTPS everywhere.
- Security headers set:
Content-Security-Policy,Strict-Transport-Security,X-Content-Type-Options,Referrer-Policy. - Cookies are
HttpOnly,SecureandSameSite. - CSRF protection on state-changing forms that rely on cookies.
- CORS allows only your own origins, never
*with credentials.
Abuse and cost
- Rate limits on login, sign-up, password reset and any endpoint that calls a paid AI API.
- Spending limits and alerts on AI and cloud accounts.
Dependencies and errors
- Dependencies are real, maintained packages (check for look-alike names).
- Production error pages do not show stack traces or environment details.
Ask the AI to attack its own code
After building a feature, ask your assistant to review it as a security tester: "List ways a malicious user could access other users' data through this code." It will not catch everything, but it catches the obvious.
Key takeaways
- Authorisation on every data access is the most common gap.
- Keep secrets on the server and out of public env variables.
- Set security headers, rate limits and spending alerts before launch.
- Treat AI-generated code as untrusted until reviewed.