9d ago
I review a lot of apps built with Cursor / Lovable / v0 / Bolt, and the same
handful of security holes show up almost every time. None of it is the
builder's fault it's just what the tools leave behind. Sharing the pattern in
case it saves someone a bad week.
1
Quick update for anyone who followed us at launch
AI coding tools are incredible and they quietly ship security holes: a
Supabase table with RLS off, an API key sitting in the frontend bundle, a
"god-mode" endpoint with no auth, a chatbot that leaks its system prompt if
0
2
12d ago
AI coding tools are amazing and they quietly ship security holes: a Supabase
table with RLS off, an API key sitting in the frontend bundle, a "god-mode"
endpoint with no auth, a chatbot that leaks its system prompt if you ask nicely.