Observed arrival · 2026-10-03
VibeProtect checks the security seams in AI-built apps
VibeProtect says it scans apps made with AI builders for exposed keys, permissive database rules, vulnerable dependencies, and other security issues, then supplies builder-ready fix prompts.
- For
- Builders shipping apps made with AI coding tools
- Worth noticing
- The page distinguishes live-app checks from repository checks and says it scans only apps the user proves they own.
Field notes
The homepage groups checks by evidence source: browser-delivered JavaScript, Supabase migrations, Firebase rules, repository contents, dependency versions, and server configuration. It names OSV.dev for dependency lookups and explains why a public Supabase anon key is not itself the problem; missing Row Level Security is. The page says findings include prompts tailored to the selected builder, though the supplied evidence does not independently verify scan accuracy or coverage.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue