{"repo":"boxed-dev/vibe-coding-security","free":true,"listed":false,"github":"https://github.com/boxed-dev/vibe-coding-security","clone":"git clone https://github.com/boxed-dev/vibe-coding-security.git","description":"Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection. Same patterns behind CVE-2025-48757 (170 apps) and the Moltbook leak (1.5M API tokens).","language":null,"stars":14,"topics":["ai-coding","bolt","claude-code","cursor","lovable","mcp","nextjs","rls","security","supabase"],"license":null,"category":"security-tools","readme_excerpt":"Vibe Coding Security Before you tweet your launch, run these 69 checks. They map to the exact patterns behind the Lovable RLS CVE (CVE-2025-48757, 170+ apps, 2025), the Moltbook leak (1.5M API tokens, Feb 2026), and the April 2026 Lovable platform breach (source code + service keys of other users' projects, exposed 2.5 months). Want the full kit? 50 audit skills, 15 .cursorrules, 1 MCP config + 4 CLI recipes, 30 adversarial review prompts, 10 case studies. 5-minute install. $10 flat. → rishabhvaai.gumroad.com/l/plddbd --- In an audit published October 2025, Escape.tech scanned 5,600 real AI-generated apps across 14,600 assets (methodology). They reported 2,038 critical vulnerabilities, 400+ leaked secrets and 175 instances of exposed PII across 1,400 of those applications (findings). The secrets came straight out of frontend bundles: Stripe, OpenAI and Supabase keys sitting in client-side JavaScript. It hasn't improved since: GitGuardian's 2026 report counted 28.6M new secrets on public GitHub in 2025 (+34% YoY), AI-service secrets up 81%, and commits co-authored by coding agents leaking secrets at roughly 2x the human baseline. This is a checklist of 69 specific, testable items. Each one maps to a real incident pattern. If you can tick all 69, ship. If you can't, fix what's blocking you. Not a SaaS. Not a scanner. A flat list you run through before you push to prod. --- The 69-Point Pre-Launch Security Checklist You're 30 minutes from shipping. Stop. Run this first. The Lova","default_branch":null,"files":null,"tree":[],"storefront":"/r/boxed-dev","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/boxed-dev/vibe-coding-security/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}