tech

I Vibe Coded a Security Risk

The app worked. Nobody, including me, had checked whether it was safe.

I Vibe Coded a Security Risk

TL;DR

  • The author built an app called Tastemaker to collect writing clips and generate style guides using AI.
  • A new feature intended to connect user profiles directly to AI agents to retrieve style guides introduced a security vulnerability.
  • Another AI model identified a public registration route that should not have been public, posing a security risk.
  • The vulnerability was discovered before any user data was accessed, but the feature was immediately taken down.
  • The experience highlights the potential for 'task crossover' and the 'illusion of explanatory depth' when using AI tools, leading to overconfidence in understanding complex systems.
  • The author emphasizes the need to understand basic principles of a field, consult human experts, and not solely rely on AI's self-assurance for readiness and safety.