Articles · 19 filed
Notes for the hour before you ship.
Checklists for the hour before you point a domain at an AI-built app. Open one note, then scan the exported repository. Do not collect the whole library first.
npx @neuralaxis/vibedoctor scan --full Open first · File 01
Before you ship · if you are shipping tonight
Vibe Coding Security Checklist: 15 Things to Check Before You Ship
A vibe coding security checklist for the hour before you deploy an AI-built app: secrets, auth, RLS, APIs, leftovers, and a local scan.
01 / The problem
What quietly goes wrong.
The gap is not that models write malware. They write the happy path, then you point a domain at it.
- Is Vibe Coding Safe? The Security Risks Nobody Notices Until Production Is vibe coding safe? The security risks in AI-built apps are not sci-fi. They are missing auth, open RLS, and secrets that only show up in production.
- How API Keys and Secrets Get Exposed in AI-Generated Apps How an exposed API key happens in AI-generated code: .env in git, VITE_ prefixes, frontend bundles, chat logs, and what to rotate first.
- 10 Security Mistakes AI Coding Agents Commonly Make Ten AI coding security risks you’ll see in Cursor, Claude Code, Lovable, Bolt, Replit, and v0 — and how to catch them before production.
02 / Your stack
Does this tool have that problem?
Lovable, Bolt.new, Cursor, and Supabase fail in related ways. The checks are not interchangeable.
- How to Secure a Lovable App Before You Deploy It Lovable security checklist: Edge Functions, Secrets, Supabase RLS, auth, public previews, and what to scan after you export the repo.
- How to Secure a Bolt.new App Before Going Live Bolt.new security before you publish: WebContainer dependencies, Secrets vs VITE_, database rules, share vs publish, and a local scan of the export.
- Cursor Security Risks: What to Check in AI-Generated Code Cursor AI security is the gap between code that compiles and code that is safe to ship: accepted diffs, .env in context, MCP, and leftovers.
- Supabase Security for Vibe-Coded Apps: RLS, Auth and the Mistakes That Matter Supabase RLS security for AI-built apps: anon vs service_role, policies that lie, storage, Edge Functions, and the tests that catch them.
- Claude Code Security Checklist Before You Ship Review Claude Code permissions, sandboxing and MCP tools, then test the generated app's secrets, authorization, failure paths and privacy.
- How to Secure a Replit App Before Publishing Check Replit secrets, production settings, authorization and published bundles. Export the repository for a local VibeDoctor scan.
- How to Secure a v0 App Before Deploying to Vercel Review v0-generated Next.js code for exposed keys, unprotected server actions and database access before a Vercel production deployment.
- Windsurf Security Checklist for Cascade-Generated Code Review Cascade commands, MCP access, dependencies and generated app behavior. Run a local VibeDoctor scan before shipping a Windsurf project.
03 / Before you ship
How to look, then how to measure.
Checklists first. Then a local scan of the exported repository, not a vibe.
- Vibe Coding Security Checklist: 15 Things to Check Before You Ship A vibe coding security checklist for the hour before you deploy an AI-built app: secrets, auth, RLS, APIs, leftovers, and a local scan.
- How to Security-Test an AI-Generated Web App Before Launch A practical website security test for AI-generated apps: export the repo, abuse the API, check secrets, then run a local VibeDoctor scan.
- Your AI App Works. But Is It Production Ready? A Pre-Launch Checklist A production readiness checklist for AI-built apps: security, headers, auth, dependencies, accessibility, performance, and a final local scan.
- DPDP Rules 2025: A Developer Readiness Checklist Turn DPDP technical readiness into reviewable engineering work: data flows, notice, consent, safeguards, retention and incident evidence.
- Gitleaks Alternatives: Choose the Secret-Scanning Job Choose secret scanning for Git history, files, CI or verified credentials. Learn when to keep Gitleaks and add a broader VibeDoctor scan.
- VibeDoctor vs Semgrep: Diagnosis and Security Rules Semgrep is a security analysis engine VibeDoctor can use. See where local rules, repository diagnosis and agent repair plans fit together.
- VibeDoctor vs Snyk: Which Checks Do You Need? Compare VibeDoctor's local repository diagnosis with Snyk's security workflow, and decide when to use both on an AI-written app.
- VibeDoctor vs SonarQube: Local Fixes and Quality Gates Compare VibeDoctor's local diagnosis and agent plans with SonarQube quality gates. Keep the controls that fit your team's review workflow.