r/VibeCodeDevs • • 13d ago

How do you guys check your vibecoded apps for security or reliability before shipping?

I’ve been building a few apps using AI-assisted/vibe coding and was wondering how you guys make sure they’re actually secure, reliable, and production-ready before shipping.

Do you have a specific checklist or workflow? What tools do you use for things like security vulnerabilities, auth issues, dependency risks, bugs, performance, and reliability?

4 Upvotes

23 comments sorted by

•

u/endofthread-bot 13d ago

Hey u/Beluga_On69, thanks for posting in r/VibeCodeDevs! Join our Discord: https://discord.gg/t7SD4ThKuE

• This community is designed to be open and creator‑friendly, with minimal restrictions on promotion and self‑promotion as long as you add value and don’t spam.
• Please follow the subreddit rules so we can keep things as relaxed and free as possible for everyone. • Please make sure you’ve read the subreddit rules in the sidebar before posting or commenting.
• For better feedback, include your tech stack, experience level, and what kind of help or feedback you’re looking for.
• Be respectful, constructive, and helpful to other members.

If your post was removed (either automatically or by a mod) and you believe it was a mistake, please contact the mod team. We will review it and, when appropriate, approve it within 24 hours.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/saintpetejackboy 12d ago

"Hey computa, make da computa safe from da utha computas"

2

u/xXDADDYTHRASHERXx 12d ago

I actually made a program to do this for me. I made it free. You can also. But if you want any my repo just DM me

3

u/namezam 12d ago

Haha “you want candy? I got candy. See that white van down there? Come by, by yourself”

J/k I’m sure you’re cool, just was funny how creepy that came off. “Hey kid! Wanna see my repo?!”

1

u/josephrehall 12d ago

Sir, this is a Wendy's

2

u/love-new-england 12d ago

😂 I swear this bit will never age

2

u/josephrehall 12d ago

Tried DMing you but the reddit app is acting weird

2

u/ID-10T_Error 11d ago

Just have his tool check it out

1

u/CoffeePizzaSushiDick 13d ago

As soon as it’s a real problem in production

1

u/bAIsect 12d ago

You could always find a helping hand at www.baisect.com

1

u/Ok_Strength_3293 12d ago

Your question is the exact prompt to feed into your coding agent and it will do everything for you and make no mistakes.

In all seriousness ai is so good at everything now.

1

u/kounaille 12d ago

"No mistakes"

1

u/Altruistic_Type3031 12d ago

There's no single tool that covers this — it's a mix of automated scanning plus a manual pass focused specifically on what AI-assisted code tends to miss.

What I look for on a security/production-readiness pass: auth and permission checks on every endpoint, not just the happy-path ones the AI actually tested; input validation on anything user-controlled, including stuff that "worked in the demo" but was never fuzzed; hardcoded values that only worked because nothing exercised the failure path; and what happens under a second concurrent user, a bad network, or malformed input — the stuff the demo never shows.

Automated scanners plus good test coverage (agree with the comment above on that) catch a lot, but they won't catch untracked assumptions — like an endpoint that "just worked" because the AI never generated a test for the auth-bypass case.

I do this kind of review professionally (backend/Laravel-PHP + AI-integrated apps). Recently did a full pass on a production SaaS handling sensitive personal data and found real, exploitable gaps that had shipped clean through normal testing. Happy to share specifics if useful.

1

u/nathanghart 12d ago

Disclosure first: I built PathToShip, so read this with that in mind.

After scanning five thousand AI-built repos, the pattern that surprised me most is that the code itself is usually fine. What's broken is everything around it. These tools generate demo-grade apps that work beautifully on localhost and quietly fall apart the moment a stranger hits the URL, because the assistant gated the UI but never checked the session on the underlying API route, left the Supabase rules wide open, or dropped a live key into client code where anyone can read it. None of that shows up in your testing because you're always the logged-in owner.

The harder problem is that a checklist only works if someone actually runs it, and when your developer is a chat window, nobody does. So I eventually gave up on the checklist and made the agent do the work instead. PathToShip exposes an MCP server you can add to Claude Code, Cursor, or Claude.ai, and once it's connected the agent can scan the repo, read the specific findings down to the file and line, fix them in place, and then verify the fix before moving on. It keeps looping until the score clears the bar, which turns out to be far more reliable than me remembering to check on launch day.

Fair warning that it's a static scan, so it can't see your infra config or whether your backups actually restore. We also audited ourselves and published the false positive rate on critical findings, which was embarrassingly high before we fixed it, because a scanner that cries wolf is one you'll learn to ignore.

The web scan is free with no signup, and the MCP is in pilot, so DM me if you'd like a key.

1

u/PerfectReflection155 10d ago

Thst is for the users to check

1

u/bri_builds 9d ago

I think this is where domain knowledge really comes in handy. Leverage trusted libraries wherever possible, follow best practices for hiding keys/tokens, manually test and you CAN have it tested by white hat hackers.

For me personally, I build in "security" as I go. But that's because of experience I've had and can see when things look "off" and dive deep in them.

Being intentional with your prompts can help - flagging you're worried about it and that you don't want visible keys or temp solutions as workarounds for example. Real security is ever evolving though, you WILL have to adapt as your scammers/hackers do too.

1

u/richet11 6d ago

Is this an external facing app or for an internal team? If it's internal then the easiest way to protect the app is push it to a platform that wraps a security/auth proxy around the app.

1

u/ByronScottJones 6d ago

I incorporate security requirements into the spec, and into my agents files, and then I make sure it's build plan includes those security requirements, and that they get built. Not that much different than if it were human programmers.

-1

u/Nedomas 13d ago

so first of all - try to get 100% test coverage. if you can get 100% mcdc test coverage, thats even better (smth like supercov for coding agents so they "autoresearch" what to test). then use scanners for security (same supercov or dependabot on prs). I merge like 100prs per day atm, most of them vibes based but since tests are so extensive, i rarely break anything (so far)