BlogSecurity writing for people
Security writing for people
building real software.
Field notes from auditing AI-generated codebases. Patterns we see, fixes that work, and what the next wave of code is doing to security.
More articles
3 posts
Security7 min readWhy Traditional Static Analysis Fails Vibe-Coded Apps
Traditional static analysis passes AI code that compiles but behaves insecurely. Here is why SAST tools like Semgrep miss the logic flaws in vibe-coded apps.
Security9 min read5 Common Security Hallucinations in Cursor and Bolt.new
AI security hallucinations are the hidden flaws Cursor and Bolt.new leave behind, from slopsquatting to open API routes. Here are the five we see most often.
Security5 min readThe Vibe-Coder's Manifesto: Why Vibe-Coding Security is the New Standard
Vibe-coding security is a branch of AI-coding security. It focuses on finding logic-based flaws in apps made by AI agents like Cursor or Bolt.new.