My job at Google is thinking like an attacker. If I were attacking your vibe-coded app, these are th

Saedf · LinkedIn · source

My job at Google is thinking like an attacker. If I were attacking your vibe-coded app, these are the 30 doors I’d try first.

Go through this before any user signs up:

BEFORE YOU PUSH

  1. Add .env to .gitignore before your first commit
  2. Run secret scanning (Gitleaks) as a pre-commit hook
  3. Rotate any key that has ever touched GitHub, even for 5 minutes
  4. Move every API key out of your frontend bundle
  5. Pin your versions and commit your lockfile

AUTH & ACCESS

  1. Check auth on every API route, not just in the UI
  2. Change the ID in the URL. Can user A read user B’s data?
  3. Turn on Row Level Security for every table
  4. Use a real auth provider. Don’t roll your own
  5. Keep access tokens short-lived, and revoke refresh tokens on logout
  6. Do admin checks on the server, never in the frontend
  7. Rate limit login, signup and password reset

INPUT & DATA

  1. Validate everything on the server. The client lies
  2. Use parameterised queries. No string-built SQL
  3. Escape user content before you render it
  4. Lock CORS to your own domains, never ”*”
  5. Make storage buckets private by default
  6. Process file uploads in a sandbox, away from your app server
  7. Verify webhook signatures (Stripe, GitHub, etc.)

AI & AGENTS

  1. Set hard spending caps on OpenAI, Anthropic and your cloud
  2. Rate limit your AI endpoints before someone drains your credits
  3. Treat anything the model reads as untrusted input
  4. Never let the model run tools, SQL or shell commands without limits
  5. Check that the packages your AI suggested actually exist
  6. Read every CLAUDE.md, SKILL.md and MCP config like it’s code
  7. Keep production credentials out of your agent’s reach

WHEN IT BREAKS

  1. Return generic errors. Never show stack traces
  2. Strip secrets and PII from your logs
  3. Log who did what, so you can reconstruct an incident
  4. Back up your database and actually test a restore

AI made shipping cheap. It made attacking cheap too.

Save this for your next deploy, and send it to the mate who ships on Fridays :D