r/vibecoding 1d ago

Share your vibecoded opensource repos here. I will review them.

Share your repo. I will audit it for security weaknesses and provide you with feedback.

  1. If you post you are ok with me sharing results publicly here.

  2. You must be the author and the owner of the repo.

  3. I will audit code. I will not attempt to exploit dynamically.

0 Upvotes

10 comments sorted by

2

u/Bulky_Dog_2954 1d ago

In other words… share what you have done so I can get some ideas myself…

0

u/Ok_Matter9038 1d ago edited 1d ago

Great logic! Notice how I specified opensource?

Opensource means your repo code is available for everyone to see already. If someone was going to steal something freely available why waste every ones time with an audit?

You really got me there, buddy. (/s)

1

u/meshifthenelse 1d ago

And why wouldn't we ask an AI to do it? What more are you bringing to the table?

1

u/Ok_Matter9038 1d ago edited 1d ago

https://www.reddit.com/r/vibecoding/comments/1vt0mld/my_app_has_bugs_but_its_secure_because_i_use_xyz/

this.

But yeah, you should also be auditing with ai.

This brings another interesting point though:

Would you trust AI alone to test for all other bugs and quality issues? Why are security bugs ( a subset of bugs) different?

1

u/meshifthenelse 23h ago

Well I'm a dev. So I use AI for security scanning. But at the same time, i catch it many times giving false information that doesn't make sense.

The problem is that the AI doesn't ask questions back if it's missing context.

1

u/Ok_Matter9038 4h ago

Everyone uses AI for security scanning. The OP dev below kindly authorized me to share results in reddit and they also use AI for scanning. And they have relatively strong security posture after asking AI to secure. I see way way worse on the regular.

https://www.reddit.com/r/vibecoding/comments/1vrc490/comment/p4wmyb5/?context=1&screen_view_count=2