← All articlesWRITING

5 security holes I look for in every AI-built app

AI coding tools can get an app to a working demo fast. These are the problems that usually come with it — and how to check your own app.

Tools like Lovable, Bolt, Cursor and Replit can take you from an idea to a working app in days. That’s genuinely useful. But “it works when I click through it” and “it’s safe to put real users on it” are two different things.

When I audit an app built this way, these five problems come up again and again. You can check for most of them yourself.

1. Secret keys in the front end

AI tools often put API keys — for OpenAI, Stripe, your database or email service — directly into the code that runs in the browser. Anything in the browser is visible to anyone who opens the developer tools.

Check it: open your live site, press F12, and search the page source and network requests for words like key, secret or sk_. If you find a real key, assume it’s been seen: move it to the server and create a new key.

2. The database trusts everyone

Many AI-built apps talk to the database straight from the browser, relying on database rules to decide who can see what. If those rules are missing or too loose, any logged-in user — sometimes anyone at all — can read or change every record.

Check it: log in as a normal user and try to open another user’s data by changing an ID in the address bar or in a request. You should get an error, not their data.

3. The button is hidden, but the action isn’t protected

A common pattern: the “Delete” or “Admin” button only shows for admins, so it looks secure. But the action behind that button doesn’t check who’s asking. Anyone who sends the request directly can use it.

The rule: every action must check permissions on the server, not just in what the interface shows.

4. No limits on anything

Sign-up, login, password reset and AI features often have no rate limits. That invites password guessing, fake accounts, and — if your app calls an AI API — someone running up your bill overnight.

Fix it: limit how many times one user or IP address can try each sensitive action, and set spending limits with your AI provider.

5. Nobody would notice if it broke

AI-built apps often have no error tracking, no logs you can search, and no backups you’ve actually tested. You find out something’s wrong when a customer tells you.

Fix it: add error monitoring, make sure backups run, and try restoring one once.

What to do next

None of this means you should throw away your app. Usually the code can be secured and cleaned up without starting over. Start with the first three — they’re the ones that leak data.

If you’d like a second pair of eyes, I run a fixed-price audit that covers all of this and gives you a prioritized list of fixes.

Have a similar problem?

Tell me about it. I'll reply within one business day.