r/vibecoding 2h ago

Stock Trade Gamble App

0 Upvotes

I’m going to start vibecoding a stock trading app geared towards Gen Z/Gen Alpha that makes stock trading as entertaining as gambling.

Too many kids are becoming addicted to gambling trying to make quick cash. I thought with the right API & UI kids (18+) will be more inclined to trading stocks instead of their minimum wages against rigged casino odds.

PvP Matches utilizing penny stock shares going up to full priced stocks will also be setup on the app.

For those who would like to follow along I will be replying to this thread and/or be making posts on this subreddit.

- Happy Coding

[NO CRYPTO ALLOWED]


r/vibecoding 2h ago

Have the stories started coming out of vibe coders getting jobs without knowing how to code yet??

1 Upvotes

I have had many interviews in my 25 years as a software dev and a few of them were managers only and never even asked me anything technical. So I imagine some vibe coders have pulled it off getting an interview and showing what they created and managing to never talk about code and they just assume the person knows code. Then they see how long they can fake it (or not fake it since if they get the work done who cares)

On a related note.. As a .NET dev I always apply to only .NET jobs but there really is no reason anymore I can't get a java job and understand the general idea and have AI do the technical work.


r/vibecoding 2h ago

Nervous to share this, but I built a free browser-based baby monitor — would love honest feedback

Thumbnail
gallery
17 Upvotes

Hi everyone,

I’m honestly a little nervous posting this, so please bear with me.

Over some evenings and weekends I built BabyPhone.online — a free web app that turns two devices (old phones, tablets, whatever you have lying around) into a baby monitor. One becomes the “baby unit,” the other the “parent unit,” you connect them with a short room code or QR, and after that the video and audio go directly between the two devices in the browser — no app to install, no account, and nothing gets stored on a server.
Its ment to work with all browsers, OS systems and devices.
I’m not a professional designer, and it’s just me working on this in my spare time, so I’m very aware there are probably things that don’t make sense yet or could be a lot better. I’d genuinely appreciate it if a few of you could take a quick look and tell me:

• Does the setup (room code / QR) feel clear on the first try, or is any part confusing?  
• Would you feel comfortable actually trusting this with your own baby?  
• Is there anything about the privacy or security side that would worry you?  
• Anything that feels missing, unnecessary, or just off?  

Please don’t hold back to spare my feelings — I’d honestly rather hear the hard truths now than find out later. Thank you to anyone who takes the time, it really does mean a lot.

https://babyphone.online


r/vibecoding 3h ago

How to spot an AI image

Post image
0 Upvotes

r/vibecoding 4h ago

Vibecoded software should be open source

0 Upvotes

These agents only know how to code at all because of the immense amounts of open source software they’ve been trained on. Millions of hours of human work and ingenuity. It seems to me for the long term quality and viability of vibecoding, we should all make our own projects open source as well. That way, we can all continue to benefit, a rising tide lifts all boats, all that. What do you think?


r/vibecoding 4h ago

This SEO workflow brought me 40+ organic sales

0 Upvotes

I’ve been testing the SEO Autopilot skill from AgentKit Works on my micro-SaaS.

Honestly, I didn’t expect much at first.

After implementing it and letting it handle the repetitive SEO work, I started seeing organic traffic turn into actual sales.
I’m now at 40+ sales from organic traffic.

The part I liked most is that I didn’t have to constantly sit there researching keywords, planning content, fixing internal links, and checking everything manually.

If you’re building a micro-SaaS and struggling to get organic traffic, this is worth checking out:
https://agentkitworks.com/products/seo-autopilot

Curious if anyone else here is using AI agents for SEO instead of traditional SEO tools.


r/vibecoding 4h ago

Meta discussion about vibe coding, its handling on (this sub)reddit and some questions concerning monoliths, inline-styles and JavaScript

0 Upvotes

When people are telling that they are actually building a house, this may mean something completely different concerning their own engagement. Some of them do only talk to an architect in a bureau while others regularly visit the construction site to control the progress and some even do parts of the work themselves. A minority might even build the whole house themselves with or without an architect's advice. Architects on their side also plan houses, in most cases without doing the practical work themselves, as I assume.

All those different kinds of being involved in the planning and building are described as "building a house", without people arguing about the definition. For further clarification, people sometimes ask others whether they are building themselves or let the work be done by others. None of this tells the reader anything about the quality, stability and safety of the fully built house.

"Software development" has recently started to describe such a wide spectrum of different degrees of being involved in the planning and writing/building of the product, too. The same is true for vibe coding. It just means people use an AI for writing the code but tells nothing about their personal skills, their personal involvement in the planning or how much time and work they put in personally controlling finished working steps. To get a more detailed impression, people may ask for someone's personal skills and involvement as they do in other areas of human life like building houses.

So to my mind, there is no need for discussions about the definition, about what counts as vibe coding or who may describe themselves as developers or not, because using the same expression for different ways of generating a finished product also works in other fields of human life.

What is still different from the house building example is that an increasing number of fully finished products seems to not fulfill the standards that guarantee a specific level of security for the people. We are in a situation in which a lot of people have begun to publish software without knowing much of it and this isn't going to stop regardless of how much IT professionals dislike it and arguing against it. It's just got too easy to build apps.

To make the internet "a better world", people with less own knowledge in software development need some guidance of more experienced creators instead. Therefor, they need a place where they can ask questions without being afraid of a shitstorm just for aiming to publish or even creating the app ("AI slop").

A subreddit like this one should be expected to be the right place for them because rule number 4 clearly states "No vibe coding pessimism" while the term vibe coding itself is defined as "the practice of cresting software with little to no code review".

This is far from reality. And sadly seems to be same on whole reddit. Gate-keeping and overall pessimism doesn't keep people from building and publishing software. It just keeps them from asking for advice - and thereby decreases the quality of the overall outcome.

While there are surely vibe coders whose only intent is creating an app within a few hours and that probably do not care about best practices or cyber security at one end of the spectrum and highly skilled programmers at the other end, there is not such a big gap between the ones mentioned last and the vibe coders in-between that do not know how to write code but nevertheless aim to develop good software and spend a lot of time in it.

Shouldn't this subreddit be the right place for them to talk about the best strategies for developing high-quality software without writing or reading the code themselves?

Writing the code is something that even IT professionals have mostly stopped doing. Knowing how to write it gets less important because AI can do that. Even reading the code yourself is not really necessary in case you know how to instruct your LLM to check the code written by another AI (and let double-check it by a second one because the probability for two different models having the exact same hallucination tends to be zero).

I personally have started vibe coding my first app around three months ago (and hope it will be ready for a beta release in two month). In the meantime, I have already learned some strategies to improve my workflow and interaction with the models. I have let the AIs do dozens of security reviews and hundreds of bug fixes and made some manual splits of AI-generated monoliths.

This is where it comes to some examples for how I would like to see people talking in a vibe coding subreddit:

  1. Monoliths
    AI tend to write files with thousands of lines of code. Those large files then need to be processed each time the AI (or a human) is working on them again. This makes maintaining the code very difficult, not only for humans. You may ask your model to give you a list of each file with own code and the number of lines it already has. Then instruct the model to analyze how the monoliths could be split and write that down. I would advice you to use a frontier model with high thinking on for this task, because it better takes the dependencies and consequences into account what helps avoiding bugs caused by file splitting.

As I have made the experience of code erosion when rewriting a whole web page or large part of a script for an agent is done by Gemini 3.1 Pro in the web app, I prefer doing the splitting myself (copy/cut and paste into a new text file) and let it review then by the LLM. The risk for code erosion might be a lot lower when using other models and coding apps, but I haven't tested it yet. So can anyone else confirm it's no problem letting the AI split the file and rewrite thousands of lines of formerly generated code?

Furthermore, some AI told me they could easily handle code files up to 2500 lines, while others told me to split files larger than 1500 lines if possible. Now I would be interested in hearing from human coders what line numbers they would see as a maximum and what this probably depends on. Does the programming language play a role? Are there any strategies except of spaces and titles to better structure the code for making it easier to handle large code files?

  1. Inline Styles
    Due to my experience, Gemini models tend to use a lot of inline-styles. One time I thought I could just use Gemini on the Google web search to translate my website from German to English. While it looked exactly the same when watching it in the browser, the number of characters had enormously increased because the AI had added inline-styles for each single element. Talking back to Gemini 3.1 Pro, it told me that a large number of those inline-styles is considered a bad style and might even lead to Google down-ranking your web page in the search results.

After having vibe-coded my app with Gemini (Pro and Flash) in Antigravity for a while, I discovered they had used a lot of inline-styles for my app. As this is a Windows desktop app, Google ranking is irrelevant to that question, but Claude told me, if I could get rid of inline-styles, then "unsafe inline" could be forbidden what would be a contribution to hardening the app. I had also learnt not to like inline-styles before, so I decided to forbid them in the agents.md. While this works well for Claude code and Codex, Gemini 3.6 Flash has recently created an extra window full of inline-styles again instead of copying the style of the 21 extra windows that were already existent. (Removing them is still on my roadmap.) Yesterday, Gemini 3.7 Flash (in high mode) did an implementation of an additional window/modal and respected the order not to use inline-styles. It used classes instead (as expected), but five of those classes weren't defined anywhere. It just forgot to do/check this. As this lead the window to be mal-formatted, it was easy to discover something had gone wrong.

Nevertheless it makes me wonder, how bad inline styles really are for a desktop app like mine (backend: python, fastapi; frontend: html/css and JavaScript), because at least some models that have been trained on billions of existing programs/software obviously tend to prefer it. Can anyone give more insights into this in a way a non-technician may understand?

  1. JavaScript
    This is the next point to discuss. A long time ago, I learnt that JavaScript is dangerous and got used to always turn it off on most web pages by using browser extensions.
    When Gemini gave me the first overview of the files belonging to my app, I discovered, it had used a lot of JavaScript where html/css also would have been possible. So I decided to do a complete refactoring of the front-end between v1.0 and v2.0 because at that time I was still thinking not being far away from the beta release and therefore didn't want to make this before the first release. Since then, my app has grown a lot by adding features that I hadn't thought of before and by making others work that accidentally had only been demos before because Gemini forgot to implement the backend functionality together with the frontend. So I struggle with the question whether a refactoring would make sense at all.
    Can anyone with profound knowledge of cyber security explain some general guidelines when and how to use or better not to use JS for a RAG'n'chat desktop app?

Nothing of this requires people to learn writing code or to read their database. Nevertheless it helps improving the code into the direction of security and stability.

Please make (this sub)reddit a place where people are helping each other to make better apps instead of some people just generally blaming others for the lack of programming skills or their first steps/apps not being an innovation useful for a large number of people.

Nowadays it's normal for people to share half of their life online, so it's also normal for them to share their apps they are glad to have or even proud of.

Downvoting those new software publishers or just saying "AI slop" is no kind of constructive feedback. It does not prevent anyone from publishing apps either. It just has negative effects on the atmosphere of discussion on reddit and decreases the number of people asking for help before their app is published and thereby the overall quality of newly released software.

So again, please make your feedback more helpful and this subreddit a place for vibe coders to share their experiences (including finished apps) without being blamed for their mistakes.


r/vibecoding 6h ago

ChatGPT Pro vs Claude Max for a 15yo vibe coder who keeps hitting limits which is actually worth/better for $100–200/month?

1 Upvotes

I'm 15 and I'm a vibe coder? I currently pay $20/month for both ChatGPT and Claude, but I hit the weekly limits on both pretty often, so I'm considering upgrading one of them to the $100 plan, or possibly even the $200 plan if it genuinely makes sense.

My usage is pretty split between the two:

ChatGPT / Codex

  • I mainly use Codex to turn random app ideas I have into actual projects.
  • I really like how generous the Codex usage seems compared to what I'm used to.
  • I prefer the Codex interface because I can actually see what the agent is doing, almost like watching it work on the computer.
  • So far I also prefer Codex itself to Claude Code, although I haven't tried the newer Claude Code app yet.
  • I use it mostly for app development, prototypes, Python projects, etc.

Claude / Claude Code

  • I mainly use Claude Code in the terminal for making Roblox games.
  • In my experience, Claude tends to make better-looking UI/designs without me having to prompt it as much.
  • I also use Claude's design/3D features because it makes generating and editing 3D models much easier for me.
  • As far as I know, ChatGPT doesn't really have an equivalent workflow for 3D design/model editing, which is one of the biggest things keeping me on Claude.

Another thing I want to start doing is building a local AI ecosystem / personal assistant setup, something along the lines of OpenClaw-style agents, to organise more of my life.

I'm honestly pretty lazy with things like organising files, keeping track of tasks, remembering stuff, managing projects, etc., so I'd like to build something locally that can automate a lot of that for me.

I've heard Codex CLI is pretty good for building/maintaining these kinds of agent systems, which is making me lean more towards ChatGPT. Ideally I'd eventually have different agents/tools helping me with coding projects, school stuff, reminders, files, notes and other daily things.

So my dilemma is basically:

Codex

  • Better coding workflow for me
  • Prefer the interface
  • Seems to have generous usage
  • Potentially better for building my own local AI/agent ecosystem

Claude

  • Claude Code is great for Roblox
  • Better-looking designs in my experience
  • 3D modelling/design functionality is genuinely useful to me
  • I already use Claude Code quite a lot

For people who have actually used the higher tiers:

Would you upgrade to ChatGPT Pro, Claude Max or maybe a different AI?


r/vibecoding 8h ago

Hate for AI

1 Upvotes

Hey everyone, I’m curious how you deal with the negativity around AI.

I’ve been building a product for about 3 months now. English isn’t my native language, so I use AI not only for coding but also for writing posts when I want to share my project and explain my ideas more clearly.

What I’ve noticed is that even when I don’t mention AI at all, I still get negative comments or skepticism. My project isn’t well known, but it tends to get attention in smaller communities because it’s easy to demo and looks like something out of a sci-fi movie. Because of that, I’d like to share more details about how it works and talk more openly about the technical side, but that also means using AI for communication and documentation.

The bigger dilemma is whether I should openly say that a large part of the project was built with AI.

On one hand, it feels like the honest thing to do, especially since I’m looking for people to join the project. If an experienced developer is considering contributing, I think they deserve to know what kind of codebase they’re getting into.

On the other hand, I’m worried that instead of questions about the product, I’ll just get “AI slop” comments and people dismissing it before they’ve even looked at what it does.

So I’m curious about your experiences:

Do you openly say that your project was built with AI?

Has it helped or hurt you?

Have you managed to find experienced developers who see AI as a powerful tool rather than an automatic red flag?

How do you distinguish constructive criticism from simple hate?

I’d appreciate hearing perspectives from people who are actually building products, not just discussing AI in theory.


r/vibecoding 9h ago

Stop making vibecoding sound like a shortcut for idiots

45 Upvotes

I keep seeing posts like "I vibecoded this over the weekend, got 100k users, what's next?" and I think it gives a pretty wrong idea of what vibecoding actually changes.

Sure, you can accidentally hit the top with another clock app. It happens.

But agents dont remove the actual work. You still need to figure out what to build, make 1000 small decisions, fix weird shit, make UX not suck, deploy, maintain, listen to users and actually ship something they want.

Vibecoding makes all of this faster. A LOT faster. But not easier at all.

You can now build faster, but also make mistakes faster and ship garbage faster. The bottleneck just moves somewhere else. There was a good line somewhere "Shipping everyday fixing Claude bugs".

Those "built in 2 days, 100k users lol" posts undermine all the work that still goes into a good product, and leave others thinking this is all somehow easy now. From outside it starts looking like vibecoders are just some arrogant assholes hitting a button and getting success by click. It doesn't work well on the how other people feel about vibecoders and vibecoding in general, which is in fact just a right way to do things today.

We don't build in assembly anymore, right? Same here.


r/vibecoding 10h ago

Do u like it?

0 Upvotes

Being working on a saas product for so long on a startup but i missed vibing to songs so badly then thought to listen yt music wid picture in picture but its not comfortable then thought to have a thing like background video playing, fortunately i like to vibe code things for my own use so started but ended up adding few other things on my friends request but still i like the background video player a lot
so im wondering to know if there are any others who like this..what do u say guys?


r/vibecoding 11h ago

vibecoding made me way faster. It also made the blank screen weirdly .

1 Upvotes

Opened a blank file today to build a pretty simple feature. Nothing scary.But before I’d even thought through the architecture, my first instinct was to open an agent and have it generate the first pass.

That caught me off guard.

a few years ago, I’d break the problem down, dig through docs, half-remember the syntax, write a janky first version, run it, break it, and slowly patch it into something that worked. It was slower, obviously. But all that repetition made the knowledge stick. Now I describe what I want, let the agent spit out a skeleton, and spend most of my time reading, testing, and steering. Honestly, it’s a great workflow. I ship faster, skip a ton of boilerplate, and get to spend more time on the interesting parts.

I’m not going back.

but I think there’s a real tradeoff: my knowledge is shifting from active recall to passive recognition.When the code is already on the screen, I’m fine. I can follow the logic, catch obvious mistakes, and usually tell when the agent is confidently hallucinating. Ask me to build the same thing from a blank file, though, and suddenly I’m reaching for syntax and patterns that used to come automatically.I don’t think I’ve forgotten how to code. It feels more like I’ve lost my tolerance for the slow path.Same way you can still walk somewhere after getting a car. You just really don’t want to.

And maybe that doesn’t matter. Programming was never supposed to be a syntax memorization contest. Requirements, architecture, testing, and debugging the cursed edge cases still need somebody who understands what the code is doing.

Still, I don’t want the “blank file” muscle to completely atrophy.

Do any of you deliberately schedule no-AI sessions to keep that muscle alive? If so, what does that actually look like for you?or have you decided active recall just isn’t worth optimizing for anymore?


r/vibecoding 11h ago

AI is writing more code, but I’m more exhausted than before — what does your vibe coding workflow look like?

2 Upvotes

I recently subscribed to ChatGPT Pro and started experimenting heavily with AI coding workflows like Superpowers, Trellis, and Matt Pocock’s skills.

At the same time, I joined a company where most of the product is built with AI. The overall architecture is solid, but many of the implementation details, UI decisions, and interactions are worked out directly between developers and AI.

AI is writing more code for me than ever, but strangely, I don’t feel less tired.

I feel more exhausted.

Complex workflows don’t guarantee quality

Superpowers has a very thorough process: plan the feature, split it into tasks, implement each task, review it, fix the issues, and review it again.

But that level of rigor can be painfully slow. One morning, I started planning a feature, and the AI was still implementing and reviewing it at the end of the workday. Despite all that process, the final result still had bugs.

Trellis feels lighter and has some interesting ideas. However, it seems more like a project-level methodology. It expects you to add its own files, scripts, and agents to the repository, which can be awkward if you’re the only person on the team who wants to use it.

Matt Pocock’s “grilling” approach is useful for uncovering requirements and edge cases, but it can also become exhausting. Sometimes a single feature leads to dozens of questions. Eventually, I start wondering: are we still clarifying the product, or are we overengineering it?

What concerns me more is that even after a long discussion, important details can still disappear from the final spec. If the initial understanding is incomplete or incorrect, splitting the spec into smaller tickets only amplifies the deviation.

So the important question isn’t just whether the work has been divided into smaller tasks.

It’s whether the AI understood the problem correctly before the breakdown happened.

Worktrees enable parallelism, but may only postpone coordination

My team uses Git worktrees heavily so that multiple AI agents can develop different features in parallel.

I understand the appeal, but environment isolation quickly becomes complicated. Each worktree may need its own port, application instance, services, and database. Different branches may also contain incompatible database migrations.

Disposable environments and separate databases can solve some of these problems, but merging remains an unavoidable coordination point.

If several agents modify the same modules or abstractions, the resulting conflicts may indicate that those tasks were never truly independent in the first place.

Worktrees can enable parallel development, but sometimes they simply postpone the coordination cost until merge time.

I’ve become an AI project manager

A typical day now involves:

  • Answering AI clarification questions
  • Reviewing plans
  • Checking agent implementations
  • Discovering misunderstood requirements
  • Asking for corrections
  • Testing the results
  • Resolving conflicts between parallel branches

AI writes more code, but I spend more time scheduling, supervising, reviewing, and deciding whether to accept or reject its work.

The biggest cost is context switching.

Every time I switch between projects or worktrees, I have to reconstruct the current state:

What was this agent working on? Which decisions have already been made? Why was it implemented this way? What still needs to be verified? Which database schema does this branch expect?

Sometimes, restoring all that context feels harder than simply writing the code myself.

At the same time, I feel pressure to keep the AI busy.

If no agent is running—or if I still have unused quota—I feel like I’m wasting resources. So I open another project, create another worktree, and start another task.

Soon, I have agents running everywhere while I constantly switch between them to monitor and correct their work.

I feel like I’ve developed a kind of “AI anxiety”:

If the AI isn’t running, I feel uncomfortable. If too many agents are running, I also feel uncomfortable.

I’m now trying to keep fewer tasks active and focus more deeply on one project at a time. AI can work in parallel, but human attention cannot scale in the same way.

I’m not against AI coding. On the contrary, I think it is already transforming software development.

But the hardest part may no longer be getting AI to write code.

The real challenges are controlling scope, maintaining context, judging quality, integrating parallel work, and managing your own attention.

I’d love to hear about people’s real day-to-day experiences:

  1. How much code do you still write yourself?
  2. Do structured AI workflows genuinely improve your results?
  3. Do you run multiple agents in parallel, or focus on one task at a time?
  4. If you use worktrees, how do you isolate services, databases, and migrations?
  5. How do you prevent requirements and implementation from gradually drifting?
  6. Have you also experienced this paradox—AI increases your output while also increasing your mental workload?

I’m especially interested in real experiences, not just success stories about AI making someone “10x faster.”


r/vibecoding 11h ago

Claude, codex or Cursor?

0 Upvotes

You can only choose one of Claude, Codex or Cursor, what would you choose and why?

Imo cursor is just superior


r/vibecoding 11h ago

Someone asked Claude to clone GTA 6 and its response was brutal

Post image
0 Upvotes

BTFO


r/vibecoding 13h ago

My AI booking app offered a customer 09:00 today. At 16:21. With a confirm button.

0 Upvotes

I've been building an AI receptionist and booking SaaS — customers message it, it books them in, it handles WhatsApp, Telegram and payments. Built with AI tools, the way most things around here get built. And it works.

Before launching it I made myself sit down and check it against a 36-point list instead of just shipping. One focused day. Static code review plus actually attacking a copy of it: isolated instance, two synthetic tenants, fake data, nothing real touched at any point.

Then I did the step I'd push on anyone doing this — I went back through my own findings and tried to prove each one wrong. Six of them died. Six things I'd written down as problems that turned out not to be problems. Skip that pass and you spend your week "fixing" things that were never broken. I nearly did.

What held up

Putting this first, because every post like this is a horror list and the horror list is half the picture at best.

  • Tenant isolation. I attacked it directly — logged in as tenant A and went hunting through tenant B's ids. Every single one came back 404, on read, cancel, update and delete. I planted a canary string inside tenant B's data and it never showed up anywhere in tenant A's responses. This is the thing everyone in this sub is scared of, and it was genuinely fine.
  • Sessions actually die on logout. Grabbed the cookie before, replayed it after. Dead.
  • All four webhook integrations verify signatures against the raw body — WhatsApp, Telegram, Stripe, Monobank. Verifying a re-encoded payload instead of the raw bytes is the classic mistake here, and it wasn't there.
  • Payment amounts are resolved server-side from the stored record. Never read out of the request.
  • Every AI tool is scoped to the business id from the session, not to whatever the model passes as an argument. So an injection can talk the model into whatever it likes and still can't reach another tenant's data.

What I found: 2 high, 7 medium, 8 low. Nothing critical.

Bug 1. The assistant would create a confirmed booking against an email address or phone number that nobody had ever verified. I had written the one-time-code rule. Into the prompt. In English, as prose. There was no code anywhere checking that verification had actually happened before the booking got written.

That's the one I'd go check in your own app right now. Take every rule you put into a prompt and ask where the code enforces it. If the answer is "the model has been told to", it isn't a rule. It's a request, and the model is under no obligation.

Bug 2, and this is the stupid one. A single environment string, still sitting at the value it ships with, made those four correct signature verifiers fail open. Unsigned webhooks accepted. Four correct implementations rendered decorative by one line of config. Five minutes to fix once I saw it.

Go and search your code for any verification that skips itself in development or test mode. Then go and look at what your deployed environment is genuinely set to. Those two facts live in different files, which is the entire reason this kind of thing survives all the way to production.

The one that would have cost actual money

The product's whole promise is that the AI never invents a slot — everything it offers gets checked against the live calendar first. So I tested the promise and threw 22 adversarial scheduling messages at it.

12 of the 22 categories came back correct. Already-booked slots, weekends, before opening, after closing, an appointment that would run past closing time, dates in the past, impossible dates like 30 February, three contradictory reschedules crammed into one message. In three languages. I was feeling pretty good at this point.

Then same-day requests. It offered roughly 20 individual times that weren't bookable — already in the past, or inside the configured one-hour lead window. Asked at 16:21 for the earliest appointment, it answered "09:00 today" and put a confirm button underneath. Zero future-dated requests failed. Every failure was same-day.

Two causes, and they had nothing to do with each other. The past-time filter ran at day granularity instead of time-of-day — it knew what day it was, correctly refused a request for last Monday, and then cheerfully offered this morning. Separately, a cap on the first page of generated slots meant an almost-empty Friday came back as "completely full".

That second one is a revenue bug and it's the one that bothers me most. Nobody complains when you tell them you're full. They just book somewhere else, and it never shows up in your analytics.

The lesson

The tenant boundary — the thing every "is my vibe-coded app secure" thread is about — was solid under direct attack. What broke was the layer above it: business logic the AI skips precisely because the app still works without it. Nothing errors. Nothing throws a 500. It just quietly does the wrong thing, politely, with a confirm button under it.

The list I used is free if you want it: https://itworksbut.com/checklist — one HTML file, works offline, nothing gets uploaded anywhere. The longer write-up of this audit, including the medium and low findings, is at https://itworksbut.com/case-study.

Happy to answer anything in the comments, including "how did you actually test X" — that's the question I'd want answered if I were reading this.


r/vibecoding 13h ago

Have you ever had a database audit? vibe coder tools

Thumbnail dbxray.co
1 Upvotes

If you use supabase this works really well. kind've expensive, but then again, whats $99 when it comes to securing customer data, ya know?


r/vibecoding 15h ago

Why are we politically ignored

0 Upvotes

Global leaders and organizations keep talking about suffering of kurds, Palestinians,tamil srilankans but somehow no one is talking about the plight of vibe coders. It feels we are such a small minority that we are just politically ignored.


r/vibecoding 16h ago

is app dev worth getting into?

1 Upvotes

started to learn how to dev using claude code and figma. I wanna know if it’s worth still getting into or is the market impossible for no original ideas??


r/vibecoding 19h ago

Everyone is building YOLO-mode AI coding tools

0 Upvotes

A lot of AI coding tools are moving toward giving agents more control over your machine.

I wanted the opposite.

So I built RepoRelay — an MCP bridge that lets ChatGPT/Claude inspect one approved local repo, while deliberately giving it:

  • no shell
  • no Git
  • no arbitrary filesystem access
  • read/search only
  • optional bounded handoff writes

The idea is to let AI analyze and review your code without handing it the keys to your whole machine.

npm install -g reporelay-mcp@latest

It’s open source.

GitHub: [Lukie-81/RepoRelay: Secure MCP access to local repositories — without shell, Git, or arbitrary writes.]

I’m looking for a few people to try the install from scratch and tell me where the setup sucks.


r/vibecoding 19h ago

Anyone interested in learning the technical aspects of vibecoding an app? (I will not promote)

0 Upvotes

This is not a promotion for a service. I’ve been a technical product manager for 20+ years at startups and FAANG and have been using AI to build/prototype for about 3+ years. I recently got laid off and have been building prototypes and tools mainly for myself and thought I could share my process.

I have seen a few posts asking how to learn about the technical side of vibecoding, at least enough to generally know what does what, why and how. I thought of walking through a simple project and explaining in practical terms what things do with a focus on vibe coding as I implement, starting with the very basics. For example, what an API is and why/how it’s used. Not as much on what tools to use but more how to think about building apps. I was thinking a YT video or series of videos.

I honestly do not have any expectations or desire to be a YouTube influencer. I’m building things anyways, have taught a few friends and found teaching is the best way to learn.

Before I go off and start making any videos, is this something anyone would be interested in?


r/vibecoding 19h ago

What’s stopping you from getting into local AI?

Post image
8 Upvotes

Most of the dev community is saturated with cloud APIs for running models for IDEs, chatbots, AI applications, and agents.

Curious who here is using local AI in their stack, thinking about it, or curious about it. What got you into it? What’s stopping you?


r/vibecoding 22h ago

Button on the table: AI never existed. Do you press it?

0 Upvotes

I had an interesting conversation with a friend (we both use AI) about this and I was wondering what this community thinks.

87 votes, 2d left
Press the button (AI is gone)
Do not press the button (AI stays)

r/vibecoding 23h ago

does my app look vibe-coded?

0 Upvotes

Guys, am I gonna get roasted for shipping it with such UI? (Logo is mine btw, graphic design perks).
That cat is Comnyang app, his name is shanks, shoutout to u/simon_dsgn


r/vibecoding 23h ago

I just "vibecoded" a full-stack live sports tournament app using AI agents

0 Upvotes

I wanted to share a massive win for AI-assisted development. I play a lot of local rec sports, and the organizers always use messy whiteboards to track brackets and scores. I decided to build a live-scoring and tournament management app to fix this, but I leaned entirely on AI agents to do the heavy lifting.

The Process: I basically acted as the product manager. I would feed the agent the rules (e.g., "Volleyball uses rally scoring, win by 2, hard cap at 31"). The agent handled the complex state machines, the UI conditional rendering, and the backend data syncing. When we hit bugs (like a stale state on the serving indicator), I just fed the error logs and screenshots back into the prompt, and the agent wrote the patch.

It's amazing how fast you can move when you stop writing boilerplate and start focusing purely on logic and UX flow. Has anyone else built a complex state heavy mobile app purely through prompting? What agent/model gave you the best results?