a public service announcement

Don't become
a LinkedIn post.

Somewhere right now, a founder's weekend app is leaking its OpenAI key to every visitor. By Thursday, nine thousand strangers will have a take about it. Not one of them will have seen the app. Check yours first.

7-day free trial. No card, no install, no discourse.

Priya N. Security engineer. Opinions my own, keys yours. Day 2
the honest one

PSA for anyone trying the plant-care app that's all over my feed this week: your OpenAI key is in the JavaScript bundle. Took me 40 seconds in dev tools.

DM'd the founder, no reply yet. If you built something with an AI builder this month, go check yours before someone less polite does.

412 reactions38 comments61 reposts
Brayden K. Founder | Ex-Founder | Future Founder | 3x LinkedIn Top Voice Day 3
the flood begins

I've been saying this for YEARS.

Vibe coding is not engineering.

Agree? ♻ Repost so your network sees it.

2,418 reactions312 comments896 reposts
Tiffani R. Fractional CISO (3 companies) · Keynote speaker · Mom Day 3

Unpopular opinion: the plant-app founder did NOTHING wrong.

The TOOLS did.

A thread 🧵 (1/27)

1,907 reactions540 comments233 reposts

how it goes

From "it works" to "a thread (1/27)" in four days.

The app is fine. The founder is fine. The leak is three things a scanner finds in under a minute, and the flood is what happens when a small mistake meets a large audience with opinions to sell.

  1. Day 0

    Ship it

    Built over a weekend by prompting. The OpenAI call failed once, the builder set dangerouslyAllowBrowser, and it worked. 1,200 signups by Sunday night.

  2. Day 2

    Forty seconds

    A security engineer opens dev tools, searches the bundle for sk-, and finds the key. Then notices the photos table has no Row Level Security. Sends a polite DM.

  3. Day 3

    The screenshot

    No reply by morning. A careful PSA goes up. Then the first "I've been saying this for years". Then the repost asking if you agree.

  4. Day 4 to 11

    The flood

    Carousels about leadership. Threads blaming the tools. Agencies with free checklists. An AI agent that would have caught it, link in comments. Q4 pipeline implications.

  5. Meanwhile

    The fix took ten minutes

    Rotate the key. Paste one prompt. Rescan. The founder did it on Day 3. The posts did not stop.

the feed

Every post here is made up.
The pattern is not.

A leaked key confirms whatever the poster already believed, and gives them a reason to mention their product. That is why it never ends. The only move is to not be the subject.

  • Nobody needs to have seen the app. The take comes first; the facts are optional.
  • Every camp gets a post. Tools bad, founder careless, security is a mindset, buy my checklist.
  • The fix does not stop it. The key was rotated on Day 3. The posts ran for two weeks.
Priya N. Security engineer. Opinions my own, keys yours. Day 2
the honest one

PSA for anyone trying the plant-care app that's all over my feed this week: your OpenAI key is in the JavaScript bundle. Took me 40 seconds in dev tools.

DM'd the founder, no reply yet. If you built something with an AI builder this month, go check yours before someone less polite does.

412 reactions38 comments61 reposts
Brayden K. Founder | Ex-Founder | Future Founder | 3x LinkedIn Top Voice Day 3
the flood begins

I've been saying this for YEARS.

Vibe coding is not engineering.

Agree? ♻ Repost so your network sees it.

2,418 reactions312 comments896 reposts
Tiffani R. Fractional CISO (3 companies) · Keynote speaker · Mom Day 3

Unpopular opinion: the plant-app founder did NOTHING wrong.

The TOOLS did.

A thread 🧵 (1/27)

1,907 reactions540 comments233 reposts
Marcus D. Leadership coach · Author of "Scale Like Water" Day 4

What the plant-app leak taught me about LEADERSHIP.

Swipe → (14 slides)

...see more

3,114 reactions201 comments1,040 reposts
Dev G. AI Automation Agency · DM "KEYS" for the free checklist Day 5

I asked ChatGPT to analyze the plant-app breach.

Its answer SHOCKED me. 👇

Comment "KEYS" and I'll send it over (connections only).

5,602 reactions4,118 comments77 reposts
Hannah O. Growth @ stealth · Building in public Day 6

We built an AI agent that would have caught this.

Link in comments.

#vibecoding #cybersecurity #founders #ai #growth #mindset

944 reactions126 comments18 reposts
Brayden K. Founder | Ex-Founder | Future Founder | 3x LinkedIn Top Voice Day 11
still going

Day 11 of the plant-app discourse.

Here's what it means for your Q4 pipeline.

...see more

1,201 reactions88 comments140 reposts

and 4,000 more

what actually leaked

Three things. Under a minute each to find.

An OpenAI key in the JavaScript

Every visitor downloads the bundle. F12, Network tab, search for sk-. Forty seconds. Whoever finds it spends on your account.

secrets.openai-key

The AI SDK running in the browser

A flag literally named dangerouslyAllowBrowser, set by the builder so the demo would work. It is how the key got into the bundle.

platform.ai-sdk-in-browser

A table without Row Level Security

The app hands out its public Supabase key by design. Without RLS, that key reads every row: every photo, every email. One request.

repo-rules.rls-disabled

the ten-minute version

Rotate. Paste. Rescan.

  1. 01

    Scan

    Paste your app's address. Prove it is yours (your builder adds a small file). The scan reads what any visitor can see and tells you, worst first.

  2. 02

    Rotate

    Any key the scan finds is already public. Revoke it where it came from and make a new one. Deleting it from the code does not un-leak it.

  3. 03

    Paste the fix

    Each finding comes with a prompt worded for your builder. Paste it, let the builder make the change, rescan to see it go green.

Paste into your builder click to select

Security fix: my OpenAI API key is in the front-end code, so anyone visiting the site can copy it.
Move the OpenAI call into a server-side function that reads the key from a server-only secret named OPENAI_API_KEY, and have the front end call that function instead.
Remove the key and dangerouslyAllowBrowser from every front-end file and from any VITE_ or NEXT_PUBLIC_ variable. Do not change the UI.

then rescan to confirm it is gone

This is the prompt for the first finding above. Yours is written for your builder, with your file and line.

questions

Fair questions.

Is this about a real app?

No. The plant app, its founder and every poster in the feed are made up. The three things that leaked are the three most common findings in apps built with AI builders, and the flood of posts is a pattern everyone on LinkedIn has watched at least once.

Isn't this a bit of fear-mongering?

The fear is proportionate to a ten-minute fix. A leaked key is found in under a minute by anyone who looks, and the fix is a prompt. We are not asking you to learn security; we are asking you to check.

Will you post about what you find in my app?

Never. We only scan apps you prove you own, findings are shown to you and nobody else, and secret values are stored redacted. You find out first, privately. That is the entire product.

What does it cost to check?

Nothing for seven days, and no card. Paste your app's address, have your builder add a small file to prove the app is yours, and the first scan runs. Pricing after that starts cheaper than one month of the AI bill a leaked key would run up.

Check your app before someone else does.

Seven days free, no card. The alternative is finding out from a carousel.