Articles · 19 filed

Notes for the hour before you ship.

Checklists for the hour before you point a domain at an AI-built app. Open one note, then scan the exported repository. Do not collect the whole library first.

npx @neuralaxis/vibedoctor scan --full

Open first · File 01

Before you ship · if you are shipping tonight

Vibe Coding Security Checklist: 15 Things to Check Before You Ship

A vibe coding security checklist for the hour before you deploy an AI-built app: secrets, auth, RLS, APIs, leftovers, and a local scan.

Read the note →

01 / The problem

What quietly goes wrong.

The gap is not that models write malware. They write the happy path, then you point a domain at it.

  1. Is Vibe Coding Safe? The Security Risks Nobody Notices Until Production Is vibe coding safe? The security risks in AI-built apps are not sci-fi. They are missing auth, open RLS, and secrets that only show up in production.
  2. How API Keys and Secrets Get Exposed in AI-Generated Apps How an exposed API key happens in AI-generated code: .env in git, VITE_ prefixes, frontend bundles, chat logs, and what to rotate first.
  3. 10 Security Mistakes AI Coding Agents Commonly Make Ten AI coding security risks you’ll see in Cursor, Claude Code, Lovable, Bolt, Replit, and v0 — and how to catch them before production.

02 / Your stack

Does this tool have that problem?

Lovable, Bolt.new, Cursor, and Supabase fail in related ways. The checks are not interchangeable.

  1. How to Secure a Lovable App Before You Deploy It Lovable security checklist: Edge Functions, Secrets, Supabase RLS, auth, public previews, and what to scan after you export the repo.
  2. How to Secure a Bolt.new App Before Going Live Bolt.new security before you publish: WebContainer dependencies, Secrets vs VITE_, database rules, share vs publish, and a local scan of the export.
  3. Cursor Security Risks: What to Check in AI-Generated Code Cursor AI security is the gap between code that compiles and code that is safe to ship: accepted diffs, .env in context, MCP, and leftovers.
  4. Supabase Security for Vibe-Coded Apps: RLS, Auth and the Mistakes That Matter Supabase RLS security for AI-built apps: anon vs service_role, policies that lie, storage, Edge Functions, and the tests that catch them.
  5. Claude Code Security Checklist Before You Ship Review Claude Code permissions, sandboxing and MCP tools, then test the generated app's secrets, authorization, failure paths and privacy.
  6. How to Secure a Replit App Before Publishing Check Replit secrets, production settings, authorization and published bundles. Export the repository for a local VibeDoctor scan.
  7. How to Secure a v0 App Before Deploying to Vercel Review v0-generated Next.js code for exposed keys, unprotected server actions and database access before a Vercel production deployment.
  8. Windsurf Security Checklist for Cascade-Generated Code Review Cascade commands, MCP access, dependencies and generated app behavior. Run a local VibeDoctor scan before shipping a Windsurf project.

03 / Before you ship

How to look, then how to measure.

Checklists first. Then a local scan of the exported repository, not a vibe.

  1. Vibe Coding Security Checklist: 15 Things to Check Before You Ship A vibe coding security checklist for the hour before you deploy an AI-built app: secrets, auth, RLS, APIs, leftovers, and a local scan.
  2. How to Security-Test an AI-Generated Web App Before Launch A practical website security test for AI-generated apps: export the repo, abuse the API, check secrets, then run a local VibeDoctor scan.
  3. Your AI App Works. But Is It Production Ready? A Pre-Launch Checklist A production readiness checklist for AI-built apps: security, headers, auth, dependencies, accessibility, performance, and a final local scan.
  4. DPDP Rules 2025: A Developer Readiness Checklist Turn DPDP technical readiness into reviewable engineering work: data flows, notice, consent, safeguards, retention and incident evidence.
  5. Gitleaks Alternatives: Choose the Secret-Scanning Job Choose secret scanning for Git history, files, CI or verified credentials. Learn when to keep Gitleaks and add a broader VibeDoctor scan.
  6. VibeDoctor vs Semgrep: Diagnosis and Security Rules Semgrep is a security analysis engine VibeDoctor can use. See where local rules, repository diagnosis and agent repair plans fit together.
  7. VibeDoctor vs Snyk: Which Checks Do You Need? Compare VibeDoctor's local repository diagnosis with Snyk's security workflow, and decide when to use both on an AI-written app.
  8. VibeDoctor vs SonarQube: Local Fixes and Quality Gates Compare VibeDoctor's local diagnosis and agent plans with SonarQube quality gates. Keep the controls that fit your team's review workflow.