I Ran a Security Audit on My Own Vibe-Coded App and Found the Scary Part Isn't What You'd Expect
Two chat routes with no rate limiting, pointed straight at a shared API key, and why that's a money problem, not a data-theft problem.
Before Build AI with AI went further, I ran a full security pass, one checkpoint at a time: auth, database, API, the AI layer, infrastructure. I expected a clean bill of health. I got a list instead.
The one that stopped me: two chat routes any logged-in user could feed made-up content, pointed straight at my shared Claude API key. No data stolen. Just a quiet way to run up my bill on prompts I never wrote.
The bigger pattern underneath it was worse. None of the routes calling Claude had any rate limiting at all. I handed over a list of routes to check, and the audit didn't trust it. It searched the whole codebase and found more AI-calling routes than I knew existed, with some of the worst gaps hiding in ones I'd forgotten about entirely.
The fixes needed no new tools. A rate limiter built on the database I already had. User input wrapped so it can't hijack the prompt. Errors that stop spilling details to whoever's looking.
The audit prompt
Audit my AI agent security. Check that:
1. User inputs are sanitized before being passed to the Claude API, look
for prompt injection risks
2. The system prompt is stored server-side only and never returned to
the client
3. Claude API outputs are validated or filtered before being displayed
or used to trigger actions
4. Every agentic action (tool call, API call, database write) is
logged with a timestamp and user ID
5. No sensitive user data (passwords, payment info, PII) is being
passed in API calls to Claude
List every gap and give me exact code to address each one.Here's the reframe that's the actual headline: the scary part of a vibe-coded app usually isn't someone stealing your data. It's someone quietly spending your money. Data theft is the breach people picture. A missing rate limiter is the one that actually shows up first, and it's boring enough that it's easy to skip checking for.
If you've shipped something with AI in it and never looked under the hood, that's the actual call to action here. Not eventually. Before the next feature, check whether every route that calls an AI model has rate limiting, input sanitization, and logging. The fixes are usually small. Finding out you need them after someone's already run up your bill is the expensive way to learn it.
Go deeper
"No Changes Needed" and an Empty Database: What Vibe Coding Actually Looks Like →
The gap between code that exists and code that runs, and why the debugging loop isn't you doing it wrong.
The Site Reverted to a Blank Word Document: Here's How the Actual Bug Got Found →
Diagnosing before touching anything, and turning an emergency fix into a real design decision.
Get new guides and builds in your inbox
No noise. New artifacts, skills, and lessons when they drop — and early access when agents launch.
Want a full structured path instead of one-off guides?
That's Learn AI with AI — a sequenced course that takes you from zero to building real things, with community and accountability built in.
Check out Learn AI with AI →