Is that vibe coded app safe? 5 checks before you download
ESET lists five checks for vetting AI “vibe coded” apps that may leak data or enable fraud.
ESET WeLiveSecurity warns that AI “vibe coding” tools can ship insecure apps because they favor features over quality. Common flaws include hardcoded API keys, missing input validation and access controls, public-by-default data, weak encryption, and no rate limiting, plus prompt injection against AI features with broad permissions. As a cautionary case, a researcher found 16 vulnerabilities, six rated critical, in one Lovable-hosted app with more than 100,000 views; Lovable said the issues were fixed. ESET recommends checking the developer’s reputation, requested permissions, privacy policy, security update process, and what an embedded AI can access.