Vibe Code in a Secured Way
AI coding is powerful. It is also risky if you are not cautious.
The AI does the work. You are responsible for everything.
The bottom-line skill for every engineer nowadays is the judgment to recognize when the AI is performing risky operations.
Know What You’re Exposing
Coding sessions can be stored remotely. LLM requests can be routed through proxies. It’s a good practice to limit what the agent and the LLM model can see.
This is not just about credentials.
When you work on any data or codebase, ask yourself: is this data appropriate for the AI to see?
When it involves customer data or personal information, think carefully about whether redaction is needed. The AI should not have visibility into data it does not need to accomplish the task.
The AI Can Ignore Your Instructions
You can ask the AI not to look at something. It can ignore you anyway.
More dangerous: the AI can be spoofed through prompt injection and tricked into performing malicious instructions.
This risk magnifies when you open up the entire internet to the agent. The internet contains everything, and not all of it is trustworthy.
Trust Your Tools and Dependencies
Only use the tools or MCP servers that you trust.
Secure your dependencies. Use tools like Dependabot to scan for vulnerabilities. Monitor supply chain attacks—remember the LiteLLM PyPI attack? That kind of compromise can propagate through your entire toolchain.
If you install an untrusted package, you are giving the AI access to whatever that package can do. And the AI might use it.
The Practical Defense
When an AI agent is running:
- Audit what data it has access to. Is it necessary?
- Audit what tools it can call. Are they all trustworthy?
- Audit what network access it has. Does it need the internet?
- Audit what code it writes. Does it make risky calls?
- Audit what credentials it carries. Are they overly permissive?
You cannot trust the AI to limit itself. You have to enforce limits at the boundary.
The most dangerous sessions are the ones where you trust the AI completely.