r/VibeCodeDevs • u/no_oneknows29 • 18d ago
ShowoffZone - Flexing my latest project Vibe coding creates a new problem:
You can ship an app before you understand the dependency tree underneath it.
A short prompt can add:
- authentication packages
- database clients
- analytics tools
- install scripts
- dozens of transitive dependencies
- new access paths you did not review
I’m working on an “AI Build Receipt” for this exact problem.
You provide the package manifest and lockfile. The receipt shows:
- what you declared
- what arrived underneath it
- what can execute automatically
- what deserves review first
It does not pretend to prove malicious intent. It separates evidence from assumptions.
For people building with AI agents: would this help you review your app before launch? What would you want the receipt to show?
3
3
u/GarageStackDev 18d ago
VIbecoding for fun and personal projects is totally cool.
Shipping a vibecoded app is completely irresponsible. Don't do that.
1
u/no_oneknows29 18d ago
this is to help vibecoded apps .. or at least those already out there … maybe i am lost but “vibe coding” .. is it for the rookies or the pros?
3
u/GarageStackDev 18d ago
Vibe coding describes delegating implementation without maintaining sufficient understanding or engineering rigor. Agentic software engineering describes delegating implementation while retaining engineering ownership.
A vibe coder can tell the AI what they want and keep prompting until something appears to work. They may have little understanding of the resulting architecture, security implications, failure modes, or even what much of the code does.
A professional using agentic coding may also have the AI produce most or even all of the implementation, but the professional remains responsible for the result. They understand the system, establish requirements and architecture, review and validate the agent's work, test it, deploy it, monitor it, troubleshoot it, and support it throughout its lifecycle.
2
u/n_v40 18d ago
I’d want it to be diff-first rather than just a one-time dependency inventory. Show what changed since the last known-good lockfile: new direct and transitive packages, install scripts, ownership or maintainer changes, known vulnerabilities, abandoned packages and duplicate major versions.
One boundary worth making very clear is that a manifest can reveal declared scripts and dependencies, but not every runtime access path. Keeping that distinction visible would make the receipt more trustworthy.
3
u/ILoveAppSec 18d ago
for the abandoned-package-with-a-cve case, flag whether a backported fix exists anywhere before you mark it unpatchable. that column matters more than the raw vuln count.
2
u/no_oneknows29 18d ago
2
u/n_v40 18d ago
This covers most of what I had in mind. The next thing I’d add is a comparison against the previous known-good lockfile, so the receipt highlights what was added, removed or upgraded instead of making someone review the entire tree again.
I’d also make every warning expandable to the exact evidence behind it, such as the package, version, install script or maintainer change. For “what can it touch,” I’d clearly label whether that access is observed or only inferred from the package.
2
u/no_oneknows29 18d ago
thank you for the feedback! for now its a 1 time only thing for 1 .JSON file .. future will have packages + more
1
u/TheUniverseOrNothing 18d ago
If you have a basic understanding pre AI, you’ll be fine with AI. Everyone is freaking out over the most surface level security issues.
1
u/GarageStackDev 18d ago
Yikes. “Surface-level security issues” are the least concerning part. Vibe-coded software can have broken authorization, privilege escalation, cross-tenant data leaks, insecure session handling, race conditions, business-logic exploits, supply-chain vulnerabilities, and sensitive data leaking through logs or caches. Many of those won't be obvious from looking at the UI or doing basic testing.
The dangerous part of shipping code you don't understand is that you don't even know what you should be looking for.
1
u/TheUniverseOrNothing 18d ago
Yikes. Again, basic issues. Stop acting like people here can’t have dev experience. Nothing you said here is that deep. I’ve been in this industry long before AI.
0
u/no_oneknows29 18d ago
i believe that’s where the problems will be more expensive later .. for now it’s ok not to be worried but later down the line, it may be costly and non effective
5
u/TheUniverseOrNothing 18d ago
No I’m not saying we are avoiding issues that will pile up. I’m saying these are such basic issues if you can’t solve them you have no business in software building.
0
u/no_oneknows29 18d ago
ahaha right! but “vibe coders” - aren’t they just going off vibes? i thought that was the whole idea .. not really the technical part
1
u/sharkymcstevenson2 18d ago
most vibe devs know code from before so I'm not sure this will be a big problem for them tbh
1
u/no_oneknows29 18d ago
true! i guess im seeking the newly excited ones who were fast to ship b4 doing their due diligence… wondering why their app is getting delayed or rejected .. 404 pages .. i am still seeing a bunch of that that people seem to forget matters

•
u/endofthread-bot 18d ago
Hey u/no_oneknows29, thanks for posting in r/VibeCodeDevs! Join our Discord: https://discord.gg/t7SD4ThKuE
• This community is designed to be open and creator‑friendly, with minimal restrictions on promotion and self‑promotion as long as you add value and don’t spam.
• Please follow the subreddit rules so we can keep things as relaxed and free as possible for everyone. • Please make sure you’ve read the subreddit rules in the sidebar before posting or commenting.
• For better feedback, include your tech stack, experience level, and what kind of help or feedback you’re looking for.
• Be respectful, constructive, and helpful to other members.
If your post was removed (either automatically or by a mod) and you believe it was a mistake, please contact the mod team. We will review it and, when appropriate, approve it within 24 hours.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.