The security risks nobody checks in vibe-coded apps
Generated code ships with a recognisable set of holes: absent authorisation, secrets in the client bundle, unbounded AI endpoints, and dependencies nobody chose. What I look for when reviewing an app that was mostly written by a model.
- Security
- AI-assisted development
- Code review
- Engineering leadership