Secure Controls Framework
Download The SCF

Vibe Coding Security - What Secure Practices Look Like in AI-Assisted Development

Secure Software Development
Secure Code Alliance (SCA) Contributor
•
September 28, 2026

Forgetting The Code Exists

In February 2025, Andrej Karpathy, a co-founder of OpenAI, described a new kind of coding he called "vibe coding," where you" fully give in to the vibes, embrace exponentials, and forget that the code even exists" (Merriam-Webster).The phrase stuck because it named something real. In practice, it means describing what you want in plain language and letting an AI assistant or agent write, run, and fix the code.

For a weekend prototype, that can be fine. For software that handles customer data or runs in production, forgetting that the code exists is not an option. Secure practices still apply. What changes is where they apply: to the prompt, the agent, the dependencies it pulls in, and the review that happens before anything ships.

The New Risks of AI-Assisted Coding

Code that works but is not safe. Veracode's2026 GenAI Code Security Report found that models produce compilable code about 100% of the time, yet the average security pass rate is only 56%. Coding-specialized models scored no better than general-purpose ones (51%versus 52%).

Misplaced confidence. In a user study published at ACM CCS 2023, Perry et al. found that participants with an AI assistant wrote significantly less secure code than those without one, and were more likely to believe their code was secure.

Hallucinated packages(slopsquatting). AI models sometimes recommend packages that do not exist. A USENIX Security 2025 study found that 19.7% of 2.23 million recommended packages were hallucinations, including 205,474 unique fake names. Attackers can register those names and wait. A 2026 preprint testing five newer models measured lower rates (4.62% to 6.10%) but found 127package names that all five models invented identically.

Leaked secrets. GitGuardian's State of Secrets Sprawl 2026 counted about 28.65 million new secrets in public GitHub commits in 2025 and an 81% rise in leaked secrets tied to AI services. It also found 24,008 unique secrets exposed in MCP configuration files, which connect AI agents to tools and data.

Agents that can be hijacked. Coding agents read issues, READMEs, web pages, and files. OWASP ranks prompt injection first in its Top 10 for LLM Applications 2025 and warns that indirect injection can arrive through external sources "such as websites or files." When that agent can also run commands, OWASP calls the danger Excessive Agency: damage caused by excessive functionality, permissions, or autonomy.

What Secure Software Development Practices (SSDP) Look Like Now

Secure practice in the age of AI is not a new discipline. It is the same discipline, applied at the points where AI changes the work.

  1. Treat AI output as untrusted input. Hold AI-generated code to the same review bar as code from a new contributor. A named human owns every merge, and "accept all" never reaches production. NIST SP 800-218A takes the same view: its practices "do not distinguish between human-written and AI-generated source code," because all source code should be evaluated for vulnerabilities before use.
  2. ‍Put security in the instructions. Veracode's 2026 results reflect models given no security-specific guidance, where they fail nearly 44% of the time. State your requirements in prompts and in the project rules files your assistant reads: parameterized queries, input validation, approved crypto libraries.
  3. Verify every dependency. Before installing a suggested package, confirm it exists, is the one you intended, and has a credible maintainer history. Use lock files, an internal registry or allowlist, and software composition analysis.
  4. Keep secrets out of reach. Never paste credentials into prompts. Store them in a secrets manager, keep them out of agent and MCP configuration files, and run secrets canning before code is committed.
  5. Give agents least privilege. Run coding agents in sandboxes with no production credentials. Require human approval for high-impact actions such as deleting data, changing infrastructure, or pushing to protected branches.
  6. Assume untrusted content is hostile. Limit what agents can read and act on from issues, pull requests, and the web. Give extra scrutiny to agent changes that touch CI pipelines, permissions, or dependencies.
  7. Automate the gates. Run static analysis, dependency scanning, secret scanning, and tests on every change, and make failures block the merge.
  8. Label AI-assisted changes. Record which changes were AI-assisted, for example in commit metadata or pull request labels, so you can trace issues back and see where AI-generated flaws cluster.
  9. Train for AI-specific failure modes. Teach teams about hallucinated packages, prompt injection, and over-trust. SP 800-218A recommends that role-based training cover threats to AI models and their possible mitigations. Perry et al. found that participants who trusted the AI less and engaged more with their prompts produced code with fewer vulnerabilities.

Guardrails, Not Bans

A ban on AI coding tools is unlikely to hold when 84% of Stack Overflow's 2025 survey respondents already use or plan to use them. The better path is guardrails that let teams move fast without losing control: clear policy, least privilege for agents, verified dependencies, automated gates, and human accountability for every line that ships. Vibe coding can stay fun for prototypes. Production software deserves secure practices, whoever or whatever wrote the code.

The Secure Code Alliance (SCA) builds these considerations into its Certified SCA Practitioner (CSCAP) program, which covers security considerations for AI model development and use and draws on NIST SP 800-218A. A developer who can demonstrate that knowledge gives clients a better answer than "the AI wrote it." Prove your code is secure. Prove your team is, too.

Vibe Coding Frequently Asked Questions(FAQ)

What is vibe coding?Vibe coding is building software by describing what you want to an AI model andaccepting the code it produces, often with little or no line-by-line review.Merriam-Webster defines it as "writing computer code in a somewhatcareless fashion, with AI assistance."

Is vibe coding secure? Not by default. AI-generated code often compiles while still containing vulnerabilities, so it needs human review, automated security testing, and dependency verification before it reaches production.

What is slopsquatting? Slopsquatting is the registration of malicious packages under names that AI models hallucinate. A developer who installs a hallucinated package without checking it may install the attacker's code instead.

How do you secure AI coding agents? Apply least privilege. Run agents in sandboxes, keep production credentials and secrets out of their reach, and require human approval for high-impact actions. Treat content the agent reads from issues, files, or the web as potentially hostile.

Sources