Don't become a LinkedIn post: the anatomy of a vibe-coded app leak
Somewhere right now a founder is shipping an app they built over a weekend by describing it to an AI. It works. It is beautiful. Its OpenAI key is in the JavaScript. By Thursday, a security engineer will have found it, a screenshot will be circulating, and the founder will have become content: the subject of an unending flood of LinkedIn posts by people who have never seen the app. Here is how it happens, and the ten minutes that stop it.
Day 0: it works
The app is a plant-care assistant. You photograph a leaf, it tells you what is wrong and what to do. The founder built it in a weekend with an AI builder: React in the browser, Supabase behind it, a call to OpenAI to read the photo. The first attempt at the OpenAI call failed, the builder set a flag called dangerouslyAllowBrowser, and the second attempt worked. The founder saw "it works". Nobody saw the flag.
They posted it. People loved it. Twelve hundred signups by Sunday night.
Day 2: forty seconds
A security engineer sees the app in her feed, opens it, and does what security engineers do when they are bored: presses F12, opens the Network tab, clicks the largest JavaScript file and searches for sk-. Forty seconds. There it is. She also notices the Supabase table for user photos has no Row Level Security, which means every uploaded photo and the email attached to it is readable by anyone with the public key, which is everyone.
She messages the founder. No reply; it is Sunday. She posts a careful, kind PSA without naming the app. It gets 400 reactions. That is the last reasonable post anyone will write about this.
Day 3: the flood
The thing about a vibe-coding leak is that it is a perfect LinkedIn event. It has a villain (the tools, or the founder, pick one), a lesson (any lesson), and a built-in reason to mention your own product. Nobody needs to have seen the app. Nobody needs to know what a bundle is. They need a take, and the takes arrive in a known order.
PSA for anyone trying the plant-care app that's all over my feed this week: your OpenAI key is in the JavaScript bundle. Took me 40 seconds in dev tools.
DM'd the founder, no reply yet. If you built something with an AI builder this month, go check yours before someone less polite does.
I've been saying this for YEARS.
Vibe coding is not engineering.
Agree? ♻ Repost so your network sees it.
Unpopular opinion: the plant-app founder did NOTHING wrong.
The TOOLS did.
A thread 🧵 (1/27)
What the plant-app leak taught me about LEADERSHIP.
Swipe → (14 slides)
...see more
I asked ChatGPT to analyze the plant-app breach.
Its answer SHOCKED me. 👇
Comment "KEYS" and I'll send it over (connections only).
We built an AI agent that would have caught this.
Link in comments.
#vibecoding #cybersecurity #founders #ai #growth #mindset
Day 11 of the plant-app discourse.
Here's what it means for your Q4 pipeline.
...see more
and 4,000 more
Every post and person above is invented. Nothing else about this is.
Why the flood never ends
The incident is small. The content opportunity is enormous. A leaked key confirms whatever you already believed: that AI builders are dangerous, that AI builders are fine and people are careless, that security is a mindset, that your agency has a checklist. Every camp gets a post, every post gets a reply, and the algorithm rewards the ones that pick a fight. The founder, who rotated the key on Day 3 and fixed the table on Day 4, is still being discussed on Day 11 by people with "Q4 pipeline" in their headline.
You cannot win the flood. You can only not be in it.
What actually leaked, and how long each took to find
- An OpenAI key in the JavaScript bundle. Found in 40 seconds with developer tools. Cost: whatever the finder decides to spend on your account before you notice.
- A Supabase table without Row Level Security. Found in another minute with the public key the app itself hands out. Cost: every row in it.
- The flag that made it possible.
dangerouslyAllowBrowser: true, in the source, where the builder put it to make the demo work.
None of these are exotic. They are the three most common findings in apps built with AI builders, and the whole list of common ones fits in twelve checks.
Day 0, the other version
Same founder, same weekend, same app. Before posting it, they spend ten minutes:
- Open the live app, press F12, search the biggest .js file for
sk-. Find the key. Wince. - Rotate the key in the OpenAI dashboard. The old one is burned the moment it shipped; deleting it from code changes nothing.
- Paste one prompt into the builder.
Security fix: my OpenAI API key is in the front-end code, so anyone visiting the site can copy it, and the "photos" table has Row Level Security turned off.
Move the OpenAI call into a server-side function that reads the key from a server-only secret named OPENAI_API_KEY, and have the front end call that function. Remove the key and dangerouslyAllowBrowser from every front-end file.
Then add a migration that enables Row Level Security on "photos" with policies so a signed-in user can only see and change their own rows (user_id = auth.uid()). Do not change the UI.
Then they post the app. Twelve hundred signups by Sunday night. On Day 2 a security engineer opens dev tools, finds nothing, closes the tab, and goes back to her weekend. On Day 3, LinkedIn talks about something else.
The point
Vibe coding is fine. Shipping is fine. The AI builders are good at what they do, and what they do is make the app work. Making the app safe is a separate ask, and it is a small one: a check before you share, a prompt for each thing it finds. The founders who end up as content are not worse builders. They skipped ten minutes.
Don't become a LinkedIn post. Check your app.
Questions people ask
Is this based on a real app?
No. The plant app, the founder and every person in the feed are invented. The three findings (a key in the bundle, a table without RLS, dangerouslyAllowBrowser) are the most common things a scan of an AI-built app turns up, and the pattern of posts that follows a public leak is one anyone with a LinkedIn account has watched happen.
Will VibeProtect post about my app's findings?
Never. We only scan apps whose owners have verified them, findings are shown to the owner and nobody else, and secret values are stored redacted. The whole point of the product is that you find out first, privately.
I already shipped. Is it too late?
No. Do the ten minutes now: check the bundle, rotate anything you find, paste the fix prompt, and run the checklist. Most leaked keys are not abused for days. The ones that become posts are the ones nobody checked.