DEV Community

Cover image for 5 security mistakes AI coding tools keep shipping (and how to catch them)
Vibe Safe
Vibe Safe

Posted on

5 security mistakes AI coding tools keep shipping (and how to catch them)

AI coding tools like Lovable, Bolt, Cursor and v0 are brilliant at one thing: making the demo work.
They are much worse at a different goal: making the app safe to put on the internet.

After looking at a lot of AI-generated code, the same five mistakes keep showing up.

1. Live secrets in frontend code

// src/lib/payments.js  ← ships to every visitor's browser
const stripe = new Stripe("sk_live_51H...");
Enter fullscreen mode Exit fullscreen mode

Anything in your frontend bundle is public. A sk_live_ key there lets anyone create charges and refunds on your account.

Fix: move secret keys to a server route or edge function and read them from environment variables. Only publishable keys (pk_live_) belong in the browser. If a secret was ever committed, rotate it: deleting the line doesn't remove it from git history.

2. Supabase tables without row-level security

The app shows each user only their own rows, so it looks secure. But the filtering happens in the frontend. With the public anon key (which is in your bundle, by design), anyone can query the table directly.

alter table public.invoices enable row level security;

create policy "Users read their own invoices"
  on public.invoices for select
  using (auth.uid() = user_id);
Enter fullscreen mode Exit fullscreen mode

Fix: enable RLS on every table in the public schema and write a policy for each operation you allow.

3. Admin routes with no auth check

/admin isn't linked anywhere, so the AI treats it as private. It isn't. Hidden is not protected.

Fix: check the session and the role on the server for every admin route and API endpoint, not just in the UI.

4. Hallucinated packages

LLMs sometimes import packages that don't exist. Attackers register those names and publish malware (this is called slopsquatting).

Fix: before installing a package you didn't choose yourself, check it exists, has real download numbers and a real repo.

5. Happy-path-only code

function saveOrder(order) {
  db.insert(order);        // missing await: errors vanish
  sendReceipt(order);      // receipt sent even if the insert failed
}
Enter fullscreen mode Exit fullscreen mode

Fix: await every promise, handle the error case, and don't send the confirmation until the write succeeds.

Catching these automatically

I built VibeSafe to flag exactly these patterns in AI-generated code, explained in plain English and mapped to the OWASP Top 10:2025. It runs on the web (no signup for the demo) and in VS Code / Cursor.

It's not a pen test and it won't replace an audit, but it catches the mistakes that show up again and again before your users find them.

What's the worst thing you've seen an AI coding tool ship? 👇

Top comments (0)