Every vibe coder's security prompt:
Bookmark it. Paste it into Claude Code before you launch:
"My vibe-coded app is about to get hacked.
- Move every API key out of the frontend
- Rotate any key that ever touched GitHub
- Turn on row-level security on every table
- Check auth on every API route, server-side
- Rate limit login, signup and anything that costs money
- Validate every input on the server
- No string-built SQL, use parameterized queries
- Lock CORS to my own domain
- Make cookies httpOnly, secure and sameSite
- Hash passwords with argon2 or bcrypt
- Never trust a user ID sent from the client
- Hide stack traces in production
- Scan dependencies for known vulnerabilities
- Add security headers
- Set spending limits on every paid API
- Find every hole before someone else does."
Your app's getting rekt without this. Don't ship vulnerable code. 🛡️
Bookmark it. Paste it into Claude Code before you launch:
"My vibe-coded app is about to get hacked.
- Move every API key out of the frontend
- Rotate any key that ever touched GitHub
- Turn on row-level security on every table
- Check auth on every API route, server-side
- Rate limit login, signup and anything that costs money
- Validate every input on the server
- No string-built SQL, use parameterized queries
- Lock CORS to my own domain
- Make cookies httpOnly, secure and sameSite
- Hash passwords with argon2 or bcrypt
- Never trust a user ID sent from the client
- Hide stack traces in production
- Scan dependencies for known vulnerabilities
- Add security headers
- Set spending limits on every paid API
- Find every hole before someone else does."
Your app's getting rekt without this. Don't ship vulnerable code. 🛡️