ciso.diy
AI-Built / Vibe-Coded App Security Posture Kit preview
Compliance vibe codingAI-built appsSupabaseVercel

AI-Built / Vibe-Coded App Security Posture Kit

Your AI builder shipped fast. Did it also ship a public database, a leaked API key, and a coding agent that will run whatever it reads next? A stack assessment, not a platform one — builder, database, hosting, AI coding tool and MCP, embedded agent — for the founder who needs to know what is exposed before it becomes an incident.

What this actually gives you

  • A stack, not a platform. Builder, database-as-a-service, hosting, AI coding tool and MCP, embedded agent — each with its own documented 2025–2026 failure pattern, and they compound. File 03 starts with a Stack Inventory because no two AI-built apps run the same combination.
  • Close to the default outcome, not an edge case: more than nine in ten scanned AI-generated apps had a critical flaw; a missing Row-Level Security policy is the commonest single cause, and one gap alone exposed over a million API tokens.
  • The gate is a checkbox, not a licence tier. An environment variable not marked sensitive is readable by anyone who reaches the hosting account — which is how a compromised third-party AI tool became an exposure at a major host in 2026.
  • The coding agent will run what it reads. MCP and agent tooling has a real CVE history including a zero-click sandbox escape, and poisoned tool output executes even against agents told to distrust it.
  • Almost nothing in this stack talks to anything else. File 06's headline is fragmentation, not a licensing gap — a low score is normal, and that is the finding to put in front of a founder. File 07 ends with a fix-it-this-week list.

Every other posture kit assesses one platform. This one assesses a pattern of stack, because that is how AI-assisted apps actually get built: a builder tool or an AI coding agent generates the application, backed by a database-as-a-service, deployed to a hosting platform, often with an embedded AI chatbot bolted on through a third-party model API. Each layer has its own documented 2025–2026 failure pattern, and they compound.

The numbers are not edge cases; they are close to the default outcome. An audit of several thousand AI-generated apps found more than nine in ten had at least one critical vulnerability. A scan of over a thousand apps on one database-as-a-service found almost all had a flaw and well over a hundred let anyone delete records with no authentication. A platform-wide Row-Level Security gap on one popular builder was confirmed in one app in ten, and a single missing policy elsewhere exposed over a million API tokens. Independent testing puts the rate at which AI-generated code introduces a security flaw at close to half.

The gate in this kit is a checkbox, not a licence tier. Every sibling kit has a "what you assume you have versus what you actually have" finding tied to a paid tier. Here it is an environment variable not marked sensitive, readable by anyone who reaches the hosting account — which is exactly how a compromised third-party AI tool turned into an exposure at a major host in 2026. File 04's Hosting & Secrets family covers that, Wrangler's secrets-versus-plain-variables distinction, preview-deployment protection and public bucket exposure, straight from the vendors' own guidance.

The coding agent will run what it reads. AI coding tools and MCP have a real, separate CVE history — including a zero-click sandbox escape at the highest severity — and poisoned tool output executes at high rates even against agents explicitly told to treat it as untrusted. A large share of scanned MCP servers are vulnerable to server-side request forgery, and thousands are reachable from the public internet. File 02 gives AI Coding Tool Access its own tab; file 03 scores it as a surface.

Embedded agents, handled as a category. An app that ships its own AI support chatbot has server-side model keys, tool scopes an injected prompt can reach, and a cost meter. The risk shape is the same whichever provider is behind it, so file 02's Embedded AI Agent Governance tab and file 03's fourth surface are provider-agnostic by design.

What you get

01 Assessment Methodology (DOCX) — why a stack rather than a platform, the numbers, the five modules mapped to four layers, run order, cross-links, and the caveat that this kit ages faster than its siblings.

02 Identity & Access Review Workbook (XLSX) — Application Auth (server-side token validation on every protected route, role model), Hosting Platform Access (team list, preview protection, connected third-party tools, DNS), AI Coding Tool Access (MCP authentication, shell allowlists, patch currency, sensitive-file exclusion) and Embedded AI Agent Governance — 16 weighted controls rolling into one score.

03 Blast Radius Scoring Tool (XLSX) — the flagship module, and the one structural departure in the series: a Stack Inventory tab comes first, because no two AI-built apps run the same combination, and rows that do not apply score N/A. Then the control questions across database/backend (RLS on every table including the ones you forgot, policies for every role, server-side authorisation, destructive operations re-checked), secrets & hosting, AI tooling and embedded agent, resolving to one score, a band on the same bands as the sibling kits, and a closure list ranked by risk-weighted points.

04 Hardening Checklist (XLSX) — Database Hardening, Hosting & Secrets, AI Tooling Hardening, and Pre-Launch & Response Readiness (including verifying package names against typosquatting and hallucinated packages, and closing debug routes). No benchmark covers this composite stack, so the README tab discloses the composite rather than pretending otherwise.

05 Data Governance Review (DOCX) — what is actually in the database once access control is fixed, including the test tables nobody remembers; storage bucket posture; and secrets and data in AI tool chat history, a governance category with no equivalent anywhere else in the series, because a developer pasting a connection string into a chat to get debugging help is a channel access control does not cover.

06 Detection Readiness Matrix (XLSX) — log sources per layer, and a headline finding that is not a licensing gap: almost nothing in this stack talks to anything else. A low score here is normal, and that is the finding worth putting in front of a founder.

07 Executive Summary Template (DOCX) — written for a solo founder as much as a board or client: a Stack assessed section so the page stands alone, and a Fix-it-this-week list of config toggles ahead of the timeline.

vibe01.json — scoring bands, stack layers, surfaces, the composite-methodology note and the module map.

A worked example throughout. Driftpoint Labs, a fictional early-stage SaaS startup on a builder, a database-as-a-service, a hosting platform, edge workers, an AI coding tool and an embedded support chatbot — with RLS on the core tables and off on the support-tickets table added last month, and a pre-launch waitlist table nobody remembered.

Where it sits. The GitHub / GitLab Security Posture Kit is the natural pair — this kit covers the app stack, that one the repository and pipeline that ship it — and the pair is cheaper than buying both. If the product has a native app, the Android and iOS posture kits cover the client side on the same scoring bands. The Shadow AI Inventory covers the AI tools a team uses beyond the coding agent. Where the AI feature runs on Vertex AI, the Google Cloud Platform Posture Kit scores the same agent risk at the cloud layer. Where the app's AI feature retrieves from a data warehouse, the Enterprise Data Warehouse & AI Pipeline Security Posture Kit scores the RAG layer and the write-back agent at the data layer. For the rest of a client's estate, the Cloud Identity Posture Bundle is the same method across M365, Google Workspace, Okta, Salesforce and the pipeline. The IR Runbook Library is the response layer — runbook 09 is data exfiltration. Hand file 07 to the Director's Cyber Oversight Kit for an investor or board pack.

Written against builder, database, hosting and AI-tool product names, defaults, and public CVE and incident reporting as of Q3 2026. This landscape moves faster than any other in the series, and the files say so. Not a penetration test — it assesses the documented configuration failure patterns of AI-built apps, not custom business logic. Scores are a prioritisation aid, not a certification, an audit opinion or an insurance-underwriting determination. Not legal advice.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-09
Pages 7