Site navigation

How Can We Solve the ‘Vibe Coding’ Security Crisis?

Elizabeth Greenberg

,

vibe coding security
‘Vibe coding’ is introducing renewed productivity and ease to development teams, but also major security risks. 

‘Vibe coding’ is revolutionising the the speed and productivity of development teams, enabling those with no or low coding skills to create programmes with AI prompts. With its great promise for enhanced efficiency, however, leaves glaring gaps in security that need to be addressed, Palo Alto Networks research shows.

AI is lowering the playing field for those looking to code, allowing users to generate pages of code through plain-text interactions with AI bots. While this is democratising the practice of coding, the programmes produced by AI often lack vital security controls, creating major vulnerabilities.

Users who are inexperienced will be unable to check AI produced code for these security failings, leaving to exposed flaws that can jeopardise data, create technical debt, and even lead to data breaches and security incidents.

Palo Alto Networks calls these coders ‘citizen developers’ which they define as “personnel without development backgrounds” who lack the expertise necessary to check the code AI develops.

Development teams, squeezed by demands from transformative tech stacks, of course see vibe coding as an innovative time-saver, but the risks are real.

“As organisations rapidly adopt these tools, a gap is widening between productivity and security. The “nightmare scenarios” are no longer hypothetical; they are documented, real-world incidents,” Palo Alto’s Unit 42 research said.

Unit 42 found instances of insecure application development leading to a breach, insecure platform logic leading to code execution and authentication bypass, and data loss resulting from a rogue database deletion.


Recommended reading


Security risks in vibe coding result from a number of AI liabilities, ranging from models’ prioritisation of function over security, context blindness, data hallucination, and over-trust in systems.

To address these risks amid rising instances of vibe coding, Unit 42 developed a framework dubbed SHIELD to guide development teams on the safe and responsible use of AI.

S – Separation of Duties – Incompatible duties should not be granted to AI agents as they may over-aggregate privileges and access data it should not.

H – Human in the Loop – Any code impacting critical functions should require a secure code review from a human as well as approval before it is integrated with existing code.

I – Input/Output Validation – For input, issuing guardrails to separate trusted instructions from untrusted data. For output, requiring AI to perform validation checks through Static Application Security Testing.

E – Enforce Security-focussed Helper Models – Create helper models to automatically validate code and perform security tests prior to deployment.

L – Least Agency – Grant minimum permissions to AI agents, and restrict access to sensitive data, with guardrails for destructive instructions like deletion.

D – Defensive Technical Controls – Disable auto-execution to allow for human-in-the-loop oversight, and employ defensive controls to manage execution.

With these in mind, development teams can better reap the benefits of vide coding whilst mitigating unnecessary risks.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data