Security Basics for AI-Generated Code
Security sounds like a specialist subject. Most of it, for a small app, is five specific things — and an AI will leave at least one of them open almost every time, because you did not ask.
It is not being careless. It is answering the question you asked ("make this work") and not the one you did not ("make this safe").
1. Secrets in the wrong place
Covered in the last stage, and it leads the list because it costs real money. Anything in a web page is public. Keys belong on a server, never in browser code.
Search your project for anything that looks like a long random string. If you find one in a file the browser downloads, that is a live problem.
2. Trusting whoever is asking
This is the one people miss entirely, because the app looks fine.
Say your app shows an order at /order/1043. What happens if someone types /order/1044? If your app only hides other people's orders in the interface — but the server hands them over to anyone who asks — then everyone's orders are public. The button being missing is not protection.
The rule: every request must check who is asking and whether they are allowed, on the server, every time. Not just the ones your buttons can reach.
Ask directly: if someone changed the id in this request to a different user's, what stops them?
3. Putting user text straight on the page
If someone can type something that other people will see — a name, a comment — then someone will eventually type something that is not text but instructions. Done badly, the browser runs it.
The fix is standard and boring: treat what people type as text to display, never as code to run. Ask whether user input is escaped before it is shown.
4. No limits on anything
If a form can be submitted a thousand times a minute, eventually it will be. That is a bill, a full database, or a broken app. Anything public and expensive needs a limit.
5. Sending things in the clear
Your live site should be https, not http. The s means the connection is encrypted. Most hosts do this for free automatically — but check, because "it works" looks identical either way.
How to actually check
You can go through the list by hand — the Security Checklist for AI-Generated Code is written for exactly that.
Or you can have it checked for you, which is the next stage.
One warning about asking the AI that wrote your code to also audit it: it is grading its own homework, and it tends to be generous. Use it, but do not treat a cheerful "looks secure!" as an answer.
Video deep dives for this stage
Official showcase
Community picks
No videos for this stage yet.