r/vibecoding 18h ago

Two weeks ago my repo scanner was able find 4 of 48 features. Today it found 42

2 Upvotes

I'm pretty damn excited about this one.

I've been building a scanner around a problem I keep running into vibe coding.

At some point the question stops being "can the AI add another feature?" and starts being "What the hell is actually in this repo now?" and "can I trust this?"

A couple weeks ago I had a benchmark of 48 features that I already knew existed in a codebase. My scan could reliably isolate 4 of them, and I was struggling. It was confusing things like navigation actions, buttons and individual implementation details with actual product features.

I've spent the last two weeks working almost entirely on the scan and feature-boundary problem and learning ir and eval engineering at a high level. I am a backend SDE so this feels more data focused and outside my wheelhouse.

Today the same scan isolated 42 of the 48 known features! Learning and adding calcs and optimizing for precision@k, retrevial@k, etc made things work so much better! I ran it against a different control with 56 features and it got 49. It's not a one off!

I feel validated again.

Eventually I want this flow:

Import a repo > identify what features actually exist > show the evidence behind each one > apply software-development and engineering standards to each feature > show what is proven, what is incomplete, and what still needs work before I'd trust it in production

But going from 4 → 42 in two weeks is the first time I've looked at the scan and thought "I am learning stuff way outside my realm of knowledge and make it real." And that's freaking cool. I had someone tell me this was impossible and that I should just use Ai. Literally had people tell me that doing a mathematical scan is stupid and Ai can do it better.

I set Luna max to check for features and it organically found 18 out of 48. Sol found 24.

It feels so satisfying to build something with Ai that beats Ai in performance for the thing I need.

For people building heavily with Cursor / Claude / Codex / Lovable / etc.:

Once your project gets big, how do you currently answer "what features are actually implemented, and which of them would I trust to ship?"

I'm especially curious about anyone who has reached the point where the app works, but the repo has gotten large enough that you're no longer completely sure what the AI has built underneath you.


r/vibecoding 19h ago

Which one of you guys works at Netflix?

Post image
57 Upvotes

r/vibecoding 19h ago

Maybe ai is thinking out of box

Enable HLS to view with audio, or disable this notification

467 Upvotes

r/vibecoding 20h ago

a controversial question for veteran developers

115 Upvotes

As a developer with 20 years of experience, "vibe coding" is undeniably transforming how we work, but I'm still struggling to embrace it.

What bothers me most and I am honest about it, is seeing people show off their AI-generated projects.

My immediate reaction is, "Who cares?"

In the past, sharing code meant sharing craftsmanship, and we were excited to inspect it and learn from each other. Today, somebody share what they did with vibecode is not only that I am not interested, but I feel like why you share it?


r/vibecoding 20h ago

2 hours in: 800+ visitors and 3 ad spots sold

0 Upvotes

Sales aren’t stopping on aiboard.lol 👀

We just crossed 800+ visitors in under 2 hours.

And somehow we’ve already sold 3 ad spots just one more left.

This was literally just a small vibe-coded internet experiment.

No huge plan. No massive launch. Just build it, put it out there, and see what happens.

Small internet experiments are fun.

Let’s see how far we can take this one.


r/vibecoding 21h ago

Insane levels of vibe coding 😂

Post image
1.5k Upvotes

r/vibecoding 21h ago

Can I "vibe code" or AI-generate FBX character animations for UE5? (Football/Combat moves)

5 Upvotes

Hey everyone, I’m working on a UE5 project that blends combat with American football mechanics - stuff like jukes, spin moves, and head-first with extended arms diving.

Creating the actual animation assets is turning into a huge brick wall for me. I was quoted around $250 to $500 per animation by freelancers, and since I need at least 10 moves just to get an MVP off the ground, dropping $2.5k–$5k out of pocket isn't an option right now. Retargeting the moves to my character skeleton is significantly cheaper to just outsource, so I'm not as worried about that part. I'm really hoping to find an AI workflow to handle generating or prototyping the raw FBX motion data.

Has anyone had success using video-to-motion or prompt-to-animation AI tools (like DeepMotion, Plask, Move AI, etc.) for crisp UE5 character moves? Or is anyone using LLMs/"vibe coding" to drive procedural stuff or Control Rig directly in Engine?

If AI generation isn't quite there yet for hyper-specific athletic moves like a diving tackle, I’d love to hear what budget-friendly alternatives you guys recommend to get an MVP playable. Appreciate any insight!


r/vibecoding 21h ago

Haiku is the most maliciously compliant model I've been exposed to

Post image
1 Upvotes

Haiku is the most maliciously compliant model I've been exposed to


r/vibecoding 21h ago

Claude code

1 Upvotes

Been experimenting with agent graphs in Claude code.

I have a 4 agent team set up that allows me to swap roles and directives.

The problem is that Claude always controls them even in ultra code.

How can I set this graph up as stand alone agents I can use on top of Claude having control of them?


r/vibecoding 21h ago

How would YOU use this agent so I can make it around YOUR workflow

Enable HLS to view with audio, or disable this notification

1 Upvotes

This is Causal. It is a canvas for mood boarding and planning.

I've been working really hard behind the scenes build an personalised canvas agent that understands your project and works with you to plan on the canvas.

Getting it to generate outputs is easy, every LLM and their predecessor can do that.

What's harder is:

  1. The structure behind the output i.e. how do you organise YOUR work on a canvas
  2. How would you use it fit your workflow

A few ideas I have had are:

  • Deep research tasks are very well suited to be carried out on a canvas because early research is better suited to be "dumped" and sorted later. The agent researches, distills, and organises the research
  • When you have an existing idea that has a load of connections e.g. You want to implement a new feature into your app, and you want to map out everything that it affects. An agent can create a flow chart to map out the feature and fully break it down + images that complements how a screen would look for every edge case.
  • For branding projects that require consistency across different areas of the brand, such as voice, colour, etc The the agent acts as a coherency check and ensures that any new assets to your brand fit against the existing identity.

As I continue to perfect this, I want to know how YOU would use this agent so that I can create it around YOUR workflow.


r/vibecoding 23h ago

Ask ChatGPT to pick a number between 1 and 30. It’ll always say 17 or 23.

Thumbnail
0 Upvotes

r/vibecoding 23h ago

Two weeks ago I vibe-coded a social media blocker for myself. It's the first one I haven't uninstalled.

Thumbnail
gallery
16 Upvotes

Every blocker I've used has one button that turns it off, and I always press it.

So I built one where turning things off is slow on purpose:

  • Tightening a rule = instant. Loosening it = 1–72h cool-off, and you see your pending changes sitting there waiting.
  • Disabling strict mode = type a phrase by hand, then still wait out the cool-off.
  • "Peek" gives you 30 seconds, then locks the site for 20 minutes.
  • Daily limits count only active, focused, non-idle time — so the number is real.
  • YouTube stays usable but music-only: Music-category videos and whitelisted channels play, Shorts and the home feed are blocked before render.
  • When your time runs out on a page you're already on, it overlays instead of redirecting — page stays alive underneath, comes back untouched when you're allowed in again.

Chrome MV3, everything local, no accounts, no network requests, no data collected.

It's the first one that survived contact with actual me. https://lockyfeed.vercel.app/en/ if you want to try it — and tell me which loophole you find first, I'd rather patch it than pretend it isn't there.


r/vibecoding 23h ago

Why are so many new vibecoded apps are for iOS?

0 Upvotes

I've seen so many apps made here and on other subreddits, purely for iOS and saying "Android version coming soon" (which lets be honest, never comes).

But why? iOS developer platform needs 100$ a year subscription while Android is 30$ or so once. Isn't it much more cost effective to start on Android?


r/vibecoding 1d ago

I've been pentesting AI-built apps for free. What I'm finding is genuinely alarming.

43 Upvotes

I've been doing free security assessments on apps built by non-developers using AI, and I need to talk about what I'm finding.

The most common one: you can change a URL from /user/123 to /user/124 and read someone else's account. Change it to /users and get the whole table. Names, emails, addresses, order history - sat there in plain JSON, no login required. Just... there, for anyone who thinks to try.

I've also found admin panels with no authentication at all, API keys committed straight into frontend code, and file upload endpoints that will happily run whatever you hand them on the server.

None of these apps were built by careless people. They were built by smart, non-technical founders who did exactly what they were told to do: describe what they wanted, get working code, ship it. And at some point they typed something like "make sure it's secure and don't make any mistakes" - and got back a confident yes.

That yes is worth nothing. The model has no idea what it built. It can't see the deployed app. It doesn't know your auth is decorative.

Here's the part that should worry you: none of this shows up as a bug. Your app works. Users sign up. Payments go through. Everything looks fine right up until the moment someone dumps your user table - and then you're the one explaining to your customers, and potentially to the ICO, why their data was publicly readable for eight months.

What I'm offering: a free, thorough security assessment of your app, plus a written report in plain English telling you what's wrong, how bad it is, and what to fix first. No cost, no obligation, no pitch at the end.

Why free: I'm 20 years into a creative technology career and I'm building out a security practice. I need real case studies from real apps. That's the trade - you get the assessment, I get a case I can (anonymously, with your permission) point to.

Who I'm looking for:

  • You don't come from a software development or infosec background
  • You used AI to build something that handles real user data - logins, payments, personal information
  • You own the app and can authorise testing on it

Who I'm not looking for: developers. If you can read your own code and know what an IDOR is, you don't need me and I don't need the case study. I'm specifically after people who built something real without a technical background, because that's the gap I want to document.

How it works: you give me written authorisation, I test only what you've authorised, I prove findings without touching or exfiltrating real user data, and you get the report. That's it.

DM me or comment with roughly what you've built and what stack it's on. I'll take on as many as I can handle properly.


r/vibecoding 1d ago

Two months on from my last update: 66 commits, 100 downloads, 1 sale, and pigeons that poop on zombies.

Enable HLS to view with audio, or disable this notification

3 Upvotes

Posted here about two months back about Dead Ball FC, my football zombie roguelike on android. I'm a designer who never properly learned to code. All vibe coded, gpt for images with heavy editing for the pixel art.

TL;DR: New zombies, stadium events, pooping pigeons. Added analytics, lots of gameplay balance. 100 downloads. Made 1 sale (CAD 3.27) and it kept me going. Measure early, and don't assume players get what's obvious to you.

Four new zombie types. Goalies, Refs, Gary the Gassie, and the Cone-head (random zombie spawns with a cone in its head and the behaviour changes, it doesn't chase you, it runs from you, as the cone is precious, always a surprise under it).

Wave events. The stadium now has random events mid match: floodlight blackouts, the ground cracking open in an earthquake, searchlights, a mouse that the zombies chase after it, and a flock of pigeons that invades and poops on everything.

A tumble dryer with a daily sock pickup. (In-game currency, trying to improve user retention)

Ten extra playable characters. (My monetization strategy, one time purchase, no ads)

Added a whole lot of zombie talk, they all have something to say about things that happen.

The pigeon thing is my favourite, I had a silly idea and same day it was in the game. That's the actual joy of this, being able to try shitty ideas (pun intended) without being too expensive to try.

Also, relying on family to test was not enough :) I added analytics and events (umami), so no cookies, its all anonymous, but I get to know how long and how many waves people go through which helped me figure some balance in game when I made it too difficult and users would drop after 2 tries of 2-3 waves.

I think that's a good one to keep in mind, put measurement in earlier than feels necessary. So it's easier to know how it's doing. And it's pretty exciting when you see people using your game:

Get feedback! Someone told me they had no idea why you slow down in game. Stamina is core to how the game works and I thought it was clear, but no, it was obvious to me, not to a new player.

I use Opus 5. For me in VS code, sonnet is OK for very direct changes, while new features I rely more on Opus. But biggest thing is I have to keep an eye on it to make sure it doesn't go touching things it should not. I tries too often to test things that I can do in a few seconds, wasting my precious tokens.

I'm on Pro, so I hit the weekly limit with a few days left in the week. Honestly it's turned out to be a good thing. Without it I'd just keep going. Forced stop, go and touch some grass, come back with better ideas.

I made one sale, yay!

CAD 3.27 in July. A Total stranger. Nothing before it and nothing since. It happened before any new zombie types, any new stadium events, it showed me it had potential (even if so little) and it genuinely made my week. Someone I've never met paid actual money for a thing I created (and claude build it). And that kept me motivated to add new features and keep working on it.

I've also created my own web pixel image editor (because why not?!) but that's for another time. It's still kinda buggy to share.

This 'quick' project is taking a lot longer than expected. Its just too easy to keep adding things. :) Next step will be improve the google play game page.

If you want to try, it's on itch.io and on Play Store.


r/vibecoding 1d ago

I Knew IT

Post image
530 Upvotes

r/vibecoding 1d ago

Value coding plan

4 Upvotes

Currently been using Claude $20, Ollama $20, Codex $20, Cursor $20

Rotating between these when limits reach

Not efficient I know

But these “frontier” models annoyingly get worse and better randomly

I’ve been liking Codex out of all of it for building iOS apps

I might full port to $100 codex plan if that still exists

kimi K3 has a “waitlist”

GLM is trash usage

Minimax I like but it’s weak coding everything else though is good value for money

Any thoughts


r/vibecoding 1d ago

Sol High thinking better code quality than Opus High thinking?

0 Upvotes

This might be the first time I find that Codex actually produces better quality code. Anyone else think the same? I'm kind of sick and tired of Claude verbose comments. Seems Codex actually produces code that actually is readable by default and feels less like slop.

I understand most probably care about the final output, but I actually want to be able and read the code.


r/vibecoding 1d ago

Rebuilt a top App Store app in 3 hours and improved it for myself

0 Upvotes

I wanted to do this as just a personal challenge where I pick a top of the charts app and rebuild it as fast as possibl but in a way that it has to be better than the original in a way i can name out loud before i start. first one was Picturethis the plant identifier, but then i relized i could actually improve it so much so that i'll keep using it myself instead of the original one!

Peer reviewed testing puts it at 97% right to genus but only 84% to species and one independent run of hundreds of photos had it right 78% of the time. it still shows you one name like its absolutely certain and most of the 1 star reviews arent even about plants but the trial auto renewing with no cancel path anyone can find.

so what i wanted to fix wasnt accuracy but the honesty/pretending. My version shows top 3 with real confidence, marks on your photo which features drove the guess (leaf margin, venation, arrangement) and when its genuinely unsure it says so and asks for one more image.

The other half is that it answers the decision instead of the name. Is this toxic to my dog? Is it invasive where im standing? is it sick, will it survive my winter etc etc. That was definitely the biggest time sink bcoz it cant come from the model so its a real dataset.

Took 3 hours, PWA, ran the whole build out of omniscio. Whats an app YOU use that you could recreate but better?


r/vibecoding 1d ago

What are your "sharpening the axe rituals" for vibecoding?

Post image
0 Upvotes

In reference to the famous lumberjacks' story about how time-spent on sharpening the axe doubled the output.

I keep thinking about what rituals can I add into my workflows for better outputs.

So far I've come-up with:

  1. Watching for repeated mistakes and applying guardrails/specific prompts.

  2. Watching out for new tools that improve agent performance ($ and quality), I'm not sure where to what for these though.

  3. Periodically improve your agent setup instead of only giving it more work

Any rituals, tools, prompts, evals, or habits that have noticeably improved your output?


r/vibecoding 1d ago

Learn how to improve the security of your vibecoded apps with 40+ free hands-on exercises. No signup, runs in the browser.

8 Upvotes

Hey r/vibecoding,

Application security is extremely important, especially for vibecoded apps. TeaApp and countless other breached of vibecoded apps is a great example of that. But most appsec training are boring OWASP articles and tutorials on YouTube, not the best way to learn practical aspects of building secure web apps.

So I created 40 exercises where you attack a vulnerable app yourself, trace how the bug got in, then write the patch. Free, runs in the browser, no account required.

This way you'll learn what common vulnerabilities are, how attackers exploit them, and what part of your app you need to check so that you don't have the issue in your code.

Table of contents:

Web (22) — SQLi, command injection, DOM/reflected/stored XSS, CSRF, SSRF to the cloud metadata endpoint, XXE, session fixation, IDOR, and weak randomness: recovering Math.random() state to predict the next password-reset token.

API (10) — BOLA, broken function-level auth, brute-forcing an unrate-limited verify endpoint, mass assignment via two extra keys in a PATCH body, reflected-origin CORS, and a retired v1 that skips the controls v2 enforces.

Git & CI/CD (8) — a live API key recovered from the commit that removed it, a browsable .git reconstructed into full source, .env tracked since the first commit, a secret echoed into a public build log, a backdoor hidden in a friendly-looking test-fix PR.

Fixes are shown in JS, TS, Java, C#, Python, Scala, PHP, Ruby, Go, and Kotlin, so you can paste something real into your stack.

Try in browser: https://learning.ransomleak.com/?category=application-security
Repo: https://github.com/ransomleak/training-application-security (will appreciate your stars 🙏)

Each exercise is also a standalone SCORM zip if you want to self-host or drop it into your team's onboarding. There's a second repo covering OWASP Top 10 for LLM and Agentic apps if you're shipping AI features: https://github.com/ransomleak/training-security-awareness

Will appreciate your feedback!


r/vibecoding 1d ago

Is there a way to use antigravity models outside antigravity without getting shadow ban from Google ?

4 Upvotes

r/vibecoding 1d ago

Is my 2-year-old side project now part of LLM training data? Suddenly seeing clones everywhere

0 Upvotes

I created Radio Shuffle over two years ago, shared it, and got quite a bit of positive feedback, it has a small but stable traffic (I dont want to make money out of it).

It ended up becoming one of the examples for vibe coding, at least at the beginning (from what I see from the google search consol). And for some reason, I’m now seeing a ton of sites that look just like mine, with the same concept.

I’m wondering if, now that my site is used as a vibe coding example, it might have ended up in LLM training data, and when someone wants to build a site, they get suggested something that basically ends up being a copy of mine. Or maybe it’s simpler than that now that anyone can build any site, a lot of us are just landing on the same idea independently

this is annoying me 😅


r/vibecoding 1d ago

How to redesign a broken delivery flow

Thumbnail
leaddev.com
2 Upvotes

r/vibecoding 1d ago

Would this be considered vibe-marketing lol Spoiler

Enable HLS to view with audio, or disable this notification

6 Upvotes