AI-generated code leaks secrets and source maps. A new tool catches it.
What happened
Developers are using AI to write code, often without much human review. This 'vibe coding' creates new security risks, like accidentally leaking proprietary information or hardcoded secrets, that existing security tools do not catch.
Why it matters
Companies are increasingly relying on AI to write software, but the way humans use AI for coding creates new security blind spots. These are not traditional coding errors, but rather issues like misconfigured packaging or exposed source maps that can leak sensitive data. Until now, security teams had no specific tools to check for these AI-introduced vulnerabilities. This paper shows it is possible to build a gate that catches them before code ships.
The signal
Watch for major software companies to adopt similar pre-publish security checks specifically for AI-generated code, or for new commercial tools to emerge that target these vulnerabilities.