Section 03
3Vibe Coding and Developer Vulnerability
Coined by Andrej Karpathy in early 2025, ‘vibe coding’ describes a workflow in which the developer stops writing deterministic code line by line and instead acts as a conversational curator, steering autonomous agents with natural-language prompts. It dramatically accelerates prototyping — and fundamentally alters the software supply chain, bypassing the SDLC in ways traditional AppSec programmes cannot manage.
3.1 The Ownership Paradox and Happy-Path Blindness
When applications are ‘vibed’ into existence, developers feel diminished authorship and accountability. That distance produces happy-path blindness: assistants optimize for immediate functional success over architectural integrity, error handling and security controls. ‘Accept All’ on massive AI-generated pull requests has coincided with a collapse in refactoring — from 25% of all code changes in 2021 to under 10% by 2024 — leaving compounding, undocumented architectural debt.
3.2 Hallucinated Dependencies and Slopsquatting
Models trained on unfiltered public data frequently hallucinate dependencies. A USENIX Security 2025 study of 576,000 code samples from 16 LLMs found that 19.7% of recommended packages did not exist — over 205,000 unique invented names — and 43% of them recurred on every repeated prompt. Attackers exploit this predictability through ‘slopsquatting’: registering the phantom names on npm or PyPI with malicious payloads that run the moment a developer installs them.

Text in this figure
REFACTORING SHARE · 25% · <10% · 2021 · 2024 · 100 AI-GENERATED SAMPLES · ≈9 recurring names · 19.7% hallucinated a package · Clean references

Text in this figure
01 · Hallucinate · Assistant recommends a package that does not exist. · 02 · Register · Attacker claims the predictable name on npm or PyPI. · 03 · Install · Developer accepts the suggestion and installs it. · 04 · Execute · Malicious payload runs inside the pipeline.
3.3 Flaws at the Execution Layer
- Exposed secrets. Models trained on public repositories suggest code containing hardcoded credentials, live API tokens or insecure endpoints, leading directly to credential harvesting.
- Insecure authorization. Generated code often includes flawed login flows, weak session handling or broken object-level authorization (BOLA). Models produce happy-path logic without the business context needed for rigid access control.
- Hallucinated logic. Code that compiles and looks correct may still contain subtle logical flaws that only surface at runtime.
Rule · Treat all AI-generated code as untrusted until its runtime behavior is validated
Manual review and static testing (SAST) cannot scale with the speed of generation. Security must shift from static analysis to runtime validation: enforce strict authentication before any sensitive logic executes, run untrusted output in containerized isolation, and use proof-based dynamic testing (DAST) to confirm real attack paths.
Tip: use ← → to move between sections.
