Ask an agent to “make it work” and it will. AI generated code security is mostly the study of how it made it work.

These ten mistakes show up across Cursor, Claude Code, Lovable, Bolt.new, Replit Agent, v0, and Copilot. The wrappers differ. The incentives do not: keep the preview green, keep the user talking, leave the sad path for later.

If you want the philosophy, read Is vibe coding safe?. This is the list.

1. Hardcoding the key that unblocked the demo

The call 401’d. The agent pasted the key into src/lib/ai.ts. You shipped.

Catch it: search prefixes, search VITE_ / NEXT_PUBLIC_, search git history, search the production bundle. Rotate anything that hits.

Tool notes: Lovable and Bolt have secret stores the agent will ignore if you pasted the key in chat. Cursor will read .env if it is in the workspace.

Long form: how API keys get exposed.

2. Turning the database into a public API

Supabase RLS off. Firebase rules allow read, write: if true. A Prisma app bound to a server that never checks session.user.id.

The UI filters “my rows.” The table does not.

Catch it: two users, request by id. Dashboard badges are not the test.

Supabase-specific. Lovable-specific.

3. Authentication as a React if

if (!user) return <Login />. The fetch behind the page does not ask.

v0 and Cursor are especially good at beautiful empty states that hide missing 401s.

Catch it: call the API signed out. You want failure from the server.

4. Trusting the client’s user_id, role, and price

The handler writes req.body.userId. The checkout uses req.body.amount. The profile update accepts role: "admin".

Agents do this because the TypeScript type said the field exists.

Catch it: mutate the JSON in the network panel. If the server obeys, that is the product.

5. Public buckets and guessable paths

Uploads “work” when the bucket is public and the path is /avatars/1.png. Congratulations, that is the vulnerability.

Catch it: signed-out GET of an object URL. Try the next integer.

6. Installing whatever clears the error

Bolt’s WebContainer and Cursor’s terminal make this cheap. A package with a similar name, a abandoned last-publish date, a postinstall script.

v0 and Lovable hide the install a bit more; the package.json still changes.

Catch it: read the diff of the manifest. Then scan the lockfile for known vulns. Do not ship an agent’s typo.

7. Leaving the scaffolding in the building

// TODO add auth, SKIP_AUTH=true, seed admin users, a /debug/session route, a second copy of the router. Replit and Cursor leave more of this because the files persist and the agent is polite about “not deleting your work.”

Catch it: search the diff for TODO, FIXME, bypass, temporary, debug. Delete or ticket. Do not launch with the comment as documentation of a hole.

8. Webhooks that trust the body

Stripe (or GitHub, or Resend) is “integrated.” The route parses JSON and provisions a plan. No signature. No idempotency.

Lovable Edge Functions and Bolt server functions both grow this shape when the prompt is “add payments.”

Catch it: POST garbage. It should fail. POST the same valid event twice. You should not double-provision.

9. Admin by URL, preview by hope

/admin, ?admin=1, “only people with the preview link.” Hosted builders emit public URLs. Replit and Bolt share links leak. v0 previews get forwarded.

Catch it: publish settings, workspace visibility, an admin role checked on the server. A secret path is not a role.

10. Declaring victory when a scanner did not run

The worst meta-mistake. Someone ran a tool, it skipped gitleaks, the score looked fine, they shipped. Or the agent “fixed” findings by deleting the tests.

Catch it: read coverage. not installed and timed out are not passes. Re-run the two-user test after the agent’s fix.

npx @neuralaxis/vibedoctor scan --full

VibeDoctor’s completeness grade exists because this mistake is common enough to deserve a status, not a footnote.

Where each tool usually fails first

ToolTypical first mistake
LovableRLS / service role / Edge Function without JWT
Bolt.newVITE_ secrets, open npm, share vs publish
Cursor / Claude CodeAccepted auth diffs, .env in context, leftovers
Replit AgentPublic repl, secrets in the wrong pane, leftover debug
v0Client-only checks, pretty UI over an open route

Same ten mistakes. Different first page of the manual.

What to do with the list

Do not start a new agent chat titled “make it secure.” Work the 15-point checklist against the exported repo, then the pre-launch test. Hand the agent a plan with evidence, not a vibe.

AI coding security risks are not mysterious. They are the shortest path between a prompt and a green preview. Close the short paths before you buy the domain.