惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
J
Java Code Geeks
P
Proofpoint News Feed
Recent Announcements
Recent Announcements
罗磊的独立博客
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园_首页
Hugging Face - Blog
Hugging Face - Blog
MongoDB | Blog
MongoDB | Blog
人人都是产品经理
人人都是产品经理
博客园 - 【当耐特】
雷峰网
雷峰网
D
DataBreaches.Net
B
Blog RSS Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东
V
Visual Studio Blog
Apple Machine Learning Research
Apple Machine Learning Research
N
Netflix TechBlog - Medium
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Martin Fowler
Martin Fowler
有赞技术团队
有赞技术团队
Blog — PlanetScale
Blog — PlanetScale
Engineering at Meta
Engineering at Meta

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
How to add a security gate to your vibe-coding workflow (...
문세환 · 2026-06-22 · via DEV Community

문세환

You're vibe-coding. Claude or GPT writes your backend in 10 minutes. It works. You ship it.

Three weeks later: SQL injection in production. Save function that never saved. Async endpoint blocking the event loop.

Here's how to add a security gate in 5 minutes that catches these before they ship.


The problem with AI-generated code

AI models generate code that looks correct. It passes type checks. It runs. It returns the right status code.

But structurally, it has consistent failure modes:

# Looks fine. Breaks everything.
async def get_user(user_id: str):
    result = db.query(f"SELECT * FROM users WHERE id = '{user_id}'")
    return result

# save() that doesn't save
def save_preferences(user_id: str, prefs: dict):
    validated = validate(prefs)
    return {"status": "saved", "user": user_id}   # no INSERT anywhere

# async with no await
async def send_notification(msg: str):
    requests.post(WEBHOOK_URL, json={"text": msg})  # blocks event loop

These aren't caught by mypy, pylint, or Bandit. They're structural patterns specific to AI-generated code.


Step 1: Scan locally (30 seconds)

curl -X POST https://pleasing-transformation-production-90c2.up.railway.app/v1/scan \
  -H "X-API-Key: vg_free_test" \
  -F "file=@app.py"

Response:

{
  "passed": false,
  "block_count": 2,
  "issues": [
    {
      "kind": "SQL_INJECTION_RISK",
      "severity": "BLOCK",
      "line": 3,
      "detail": "unsafe SQL formatting — use parameterized queries"
    },
    {
      "kind": "MISSING_WRITE",
      "severity": "BLOCK",
      "line": 8,
      "detail": "function 'save_preferences' has no DB write call"
    }
  ]
}

If passed: true — ship it. If not — fix the BLOCKs first.


Step 2: Add to GitHub Actions (2 minutes)

Create .github/workflows/vibeguard.yml:

name: VibeGuard Scan
on: [pull_request]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Scan changed files
        run: |
          git diff --name-only origin/main...HEAD \
            | grep -E '\.(py|js|ts|go|rb|java|php|kt)$' \
            | while read f; do
                echo "Scanning $f..."
                result=$(curl -s -X POST \
                  https://pleasing-transformation-production-90c2.up.railway.app/v1/scan \
                  -H "X-API-Key: ${{ secrets.VIBEGUARD_KEY }}" \
                  -F "file=@$f")
                echo "$result" | python3 -c "
import json,sys
d=json.load(sys.stdin)
if not d.get('passed'):
    for i in d.get('issues',[]):
        if i['severity']=='BLOCK':
            print(f'BLOCK [{i[\"kind\"]}] line {i[\"line\"]}: {i[\"detail\"]}')
    sys.exit(1)
"
              done

Add secret: Settings → Secrets → VIBEGUARD_KEY = vg_free_test

Every PR now gets scanned. BLOCK = PR fails. Green = safe to merge.


Step 3: Pre-commit hook (optional, 1 minute)

# .git/hooks/pre-commit
#!/bin/sh
for file in $(git diff --cached --name-only | grep -E '\.(py|js|ts|go)$'); do
    result=$(curl -s -X POST \
        https://pleasing-transformation-production-90c2.up.railway.app/v1/scan \
        -H "X-API-Key: vg_free_test" \
        -F "file=@$file")
    passed=$(echo "$result" | python3 -c "import json,sys; print(json.load(sys.stdin)['passed'])")
    if [ "$passed" = "False" ]; then
        echo "BLOCK found in $file — run curl scan to see details"
        exit 1
    fi
done

chmod +x .git/hooks/pre-commit

Now every commit is scanned before it's made.


What gets caught

Pattern Example Why AI generates it
SQL_INJECTION_RISK f"SELECT ... WHERE id='{x}'" f-strings are common in training data
MISSING_WRITE def save(): return {"ok": True} AI optimizes for "looking complete"
FAKE_ASYNC async def f(): return requests.get(url) copies async signature without understanding
CORS_WILDCARD allow_origins=["*"] + credentials copies boilerplate without understanding interaction
STUB_SKELETON def process(data): return {} placeholder that AI forgot to implement
HARDCODED_TABLE 40-key dict instead of DB query AI avoids DB setup complexity
SSRF_RISK httpx.get(user_url) unvalidated doesn't think about internal network access
PATH_TRAVERSAL open(user_path) unvalidated doesn't add boundary checks

9 languages supported: Python, JS, TS, Go, Ruby, Java, PHP, Kotlin, C/C++.


Free tier

  • vg_free_test key: full Pro features, 50 files/day
  • No signup required
  • Code not stored — processed in memory, discarded after scan

API: https://pleasing-transformation-production-90c2.up.railway.app
GitHub: https://github.com/Moonsehwan/aina-scan


The whole point: vibe-coding is fast. The gate should be faster. 30-second scan before you merge beats a 3-week postmortem.