AI agent security14 min read
AI agent security checklist for developers
A practical, reviewable checklist for the controls that matter before an AI agent can touch real code, systems, or customer data.
Read the checklistLoading VibeLint...
VibeLint Blog
Practical guides on prompt injection, MCP risk, agent permissions, approvals, and action logs.
A practical, reviewable checklist for the controls that matter before an AI agent can touch real code, systems, or customer data.
Read the checklistTrace untrusted instructions from their source to the model and from model output to every execution-capable sink.
An MCP server extends what Claude Code can reach. Review identity, scopes, commands, network access, and approval behavior before connecting it.
Vibe coding becomes risky when working-looking output bypasses threat modeling, authorization review, dependency checks, and controlled deployment.