Hold My Hammer

Blog / What I'm learning

Vibe coding security: I built 7 apps with AI and couldn't secure one

By ·

If you build apps with AI and you aren’t an engineer, your app can work perfectly and still be wide open. I’ve built seven of them in a little over a year, and for most of that time I couldn’t have told you how to secure a single one.

This is what I’ve learned since, written for people who are where I was.

Why don’t people like me think about security?

Because we can’t see it.

When I build with AI, I look at two things. Does it look good? Does it solve the problem? If both answers are yes, it feels finished.

I’ve flipped 13 houses with my wife. In a house, a missing lock is obvious: you can walk up and see the hole in the door. In software, the door looks fine from the front. The problem is somewhere I never look, in a part of the app I couldn’t read if I tried.

The AI builds what I ask for. I never asked for locks, because I didn’t know which doors existed.

What are the most common ways an AI-built app is exposed?

Four come up again and again in the security checklists written for this (two good ones are linked at the end). Here they are in house terms.

1. The key is under the mat

Apps use secret keys to talk to other services, like a payment company or an AI model. If a key ends up in the part of the app that every visitor’s browser downloads, anyone can copy it and run up your bill.

Ask your AI: “Are any secret keys in code that gets sent to the browser?”

2. The back door is unlocked

Your database is where the customer information lives. Many AI-built apps ship with a database that answers anyone who asks, whether or not they’re logged in.

Ask your AI: “Can someone who isn’t logged in read or change anything in my database? Show me how you checked.”

3. The guard is checking IDs in the wrong place

An app has to decide who is allowed to see what. If that decision happens in the visitor’s browser, the visitor can change it. It has to happen on your server, where they can’t reach.

Ask your AI: “Where does the app check that a user is allowed to see this data? Is that check on the server?”

4. The office has no door

Most apps have an admin area for the owner. Sometimes it’s sitting at a public address with nothing in front of it, because nobody was supposed to know the address. Strangers find those addresses with automated scans.

Ask your AI: “List every admin page and tool, and tell me what stops a stranger from opening each one.”

What can you do this week?

Paste those four questions into whatever AI you build with, one at a time, and ask it to show its work. It takes about an hour.

That hour tells you whether your front door is open, which is more than I knew for most of a year.

If your app is about to handle real customers, payments or anything private, pay a professional to look at it before you launch. Nearly every guide on this says the same thing.

Why I’m building Mobius1

Realizing all of this is what pushed me into security.

Mobius1 is for small IT and security teams. It shows what a company is exposing on the internet and which fix should come first. It hasn’t launched yet.

I’m building it in public, including the parts that go wrong. You can follow along on LinkedIn.

Further reading

Quick answers

What is vibe coding?
Vibe coding means building software by describing what you want in plain language and letting an AI write the code. It lets people who can't program build working apps.
Is an app built with AI insecure?
Not automatically. The AI builds what you ask for, and most beginners never ask about security because they don't know what to ask. The app can work perfectly and still be open to strangers.
What should a non-developer check first?
Four things: that no secret keys sit in the part of the app visitors download, that the database refuses strangers, that permission checks happen on the server, and that admin pages are not public.
When should I get a professional to look at my app?
Before it handles real customers, payments or anything private. Until then, asking your AI the four questions in this post catches the most common gaps.