AI Development Trend Vibe Coding Sparks Security Debate, Underscoring Value of Human Expertise
Vibe coding is a development approach in which AI rapidly generates software from natural-language instructions. Former OpenAI researcher Andrej Karpathy coined the term in February 2025. The approach lowers the barrier to building apps, but it can also lead people without engineering training to overlook critical issues such as access controls, data protection and system architecture. Responsibility for cybersecurity therefore cannot be handed over to AI.
An AI-assisted app called “惜食獵人” recently came under scrutiny after vulnerabilities, including the exposure of GPS coordinates, were disclosed, prompting online debate over the security of vibe coding. The incident shows that while AI can shorten development and product-launch timelines, developers must still conduct code reviews, security testing and risk assessments themselves. Those most at risk of being replaced are people unable to distinguish good code from bad.
All Coverage
1 original reportsThe Backstory
The history behind this eventVibe Coding Boom Fuels Demand for AI Code Cleanup
Generative AI has lowered the barrier to software development, while “vibe coding” allows users to build applications through natural-language instructions with limited conventional programming. The speed can come at a cost: projects may bypass requirements analysis, architecture planning and code review. As prototypes move toward production, inconsistent business logic, security vulnerabilities and accumulated technical debt are creating a new market for software quality assurance.
Software quality specialists are responding with code-cleanup and remediation services designed to inspect AI-generated applications, repair defects and strengthen testing before deployment. The report did not identify specific providers or disclose pricing, contract values or launch dates. Industry experts cautioned that AI-assisted development still requires automated tests, human review and disciplined maintenance, as models can reproduce flawed assumptions across a codebase and amplify errors faster than traditional development workflows.
Vibe Coding Raises Security Concerns as More Than 5,000 Apps Risk Data Exposure
“Vibe Coding” allows users to direct AI in natural language to rapidly generate software, lowering barriers to development. It also enables employees with little cybersecurity experience to build corporate tools independently, creating “shadow AI” that is difficult for IT departments to control. Without authentication, such applications can directly expose medical and financial information, as well as internal presentations. The risk stems from poor deployment and access management, rather than platform vulnerabilities.
A recent RedAccess survey found that more than 5,000 Vibe Coding applications were accessible over the public internet without basic authentication, including about 2,000 tools built for corporate use. Their exposure of sensitive data shows that employee-built tools have become a gap in corporate cybersecurity governance. Companies need to immediately inventory public endpoints, add authentication and restrict data-access permissions.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →