<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>VibeProtect blog</title>
  <link>https://vibeprotect.dev/blog</link>
  <atom:link href="https://vibeprotect.dev/blog/feed.xml" rel="self" type="application/rss+xml"/>
  <description>Security guides for apps built with AI app builders, from Instant City Solutions LLC.</description>
  <language>en</language>
  <lastBuildDate>Fri, 02 Oct 2026 12:00:00 GMT</lastBuildDate>
  <item>
    <title>Don't Become a LinkedIn Post: Anatomy of a Vibe-Coded Leak</title>
    <link>https://vibeprotect.dev/blog/dont-become-a-linkedin-post</link>
    <guid isPermaLink="true">https://vibeprotect.dev/blog/dont-become-a-linkedin-post</guid>
    <pubDate>Fri, 02 Oct 2026 12:00:00 GMT</pubDate>
    <author>Frank Robles</author>
    <description>A founder ships an AI-built app Saturday. By Wednesday a stranger has the OpenAI key. By Thursday LinkedIn has 9,000 takes. The 10 minutes that prevent it.</description>
  </item>
  <item>
    <title>Vibe Coding Security Checklist: 12 Checks Before You Ship</title>
    <link>https://vibeprotect.dev/blog/vibe-coding-security-checklist</link>
    <guid isPermaLink="true">https://vibeprotect.dev/blog/vibe-coding-security-checklist</guid>
    <pubDate>Fri, 02 Oct 2026 12:00:00 GMT</pubDate>
    <author>Frank Robles</author>
    <description>Vibe coding security checklist: 12 checks before strangers use your app. Leaked keys, Supabase RLS, Firebase rules, .env in GitHub, each with a fix prompt.</description>
  </item>
  <item>
    <title>Is Lovable Secure? What It Protects, What Your App Leaks</title>
    <link>https://vibeprotect.dev/blog/is-lovable-secure</link>
    <guid isPermaLink="true">https://vibeprotect.dev/blog/is-lovable-secure</guid>
    <pubDate>Fri, 02 Oct 2026 12:00:00 GMT</pubDate>
    <author>Frank Robles</author>
    <description>Is Lovable secure? Yes. Apps built with it leak in four ways: VITE_ keys, the service_role key, tables without RLS, GitHub sync. How to check yours and fix it.</description>
  </item>
  <item>
    <title>Supabase RLS in Lovable Apps: Check Every Table in 2 Minutes</title>
    <link>https://vibeprotect.dev/blog/supabase-rls-lovable</link>
    <guid isPermaLink="true">https://vibeprotect.dev/blog/supabase-rls-lovable</guid>
    <pubDate>Fri, 02 Oct 2026 12:00:00 GMT</pubDate>
    <author>Frank Robles</author>
    <description>Supabase RLS in Lovable apps: find every table with RLS disabled, spot policies that let everyone in, and fix them with copy-paste SQL or a Lovable prompt.</description>
  </item>
  <item>
    <title>API Key Exposed in Frontend JavaScript? Do These 5 Things</title>
    <link>https://vibeprotect.dev/blog/api-key-exposed-frontend-javascript</link>
    <guid isPermaLink="true">https://vibeprotect.dev/blog/api-key-exposed-frontend-javascript</guid>
    <pubDate>Fri, 02 Oct 2026 12:00:00 GMT</pubDate>
    <author>Frank Robles</author>
    <description>API key exposed in frontend JavaScript? The 10-minute response: rotate it, check usage, move the call server-side, clean VITE_ vars, verify it is gone.</description>
  </item>
  <item>
    <title>Replit App Security: 6 Holes Agent-Built Apps Ship With</title>
    <link>https://vibeprotect.dev/blog/replit-app-security</link>
    <guid isPermaLink="true">https://vibeprotect.dev/blog/replit-app-security</guid>
    <pubDate>Fri, 02 Oct 2026 12:00:00 GMT</pubDate>
    <author>Frank Robles</author>
    <description>Replit app security: Replit is trusted, with Secrets, Auth and its own scanner. Agent-built apps still ship six holes: VITE_ keys, routes without auth, open CORS.</description>
  </item>
</channel>
</rss>
