// docs / security guides
أدلة الأمان
أدلة متعمقة ومدركة لإطار العمل لتأمين التطبيقات التي تم إنشاؤها باستخدام Cursor وClaude Code وLovable وBolt وv0 وReplit وWindsurf. تمت كتابة كل دليل ليكون مستقلاً — اختر الدليل الذي يطابق ما تفعله الآن. المزيد من الأدلة تصل هنا مع ظهور فئات الهجوم الجديدة في محرك الفحص FixVibe.
// category overview
AI- فحص أمان التعليمات البرمجية الذي تم إنشاؤه: DAST للتطبيقات المشفرة
لماذا تحتاج التطبيقات التي تم إنشاؤها AI- إلى فحص مختلف عن أدوات pentest التقليدية. يغطي فئات الثغرات العشرة التي تظهر بشكل غير متناسب في التطبيقات ذات الترميز الديناميكي، DAST مقابل SAST عندما تكون قاعدة التعليمات البرمجية نصف مولدة آليًا، وما الذي تبحث عنه في الماسح الضوئي، وكيف يمكن مقارنة FixVibe بـ Burp Suite، وOWASP ZAP، وNessus.
قراءة التمهيدي الماسح الضوئي →
// pre-ship audit
قائمة التحقق من أمان تشفير Vibe: 51 عنصرًا قبل الشحن
قائمة مرجعية عملية ومنظمة على مراحل للتطبيقات التي تم إنشاؤها باستخدام Cursor وClaude Code وLovable وBolt. سبع فئات - الأسرار، وقاعدة البيانات، والمصادقة، والعناوين، والجهات الخارجية، والنشر، والمراقبة - مع 51 عنصرًا قابلاً للتنفيذ، تم وضع علامة على كل منها قبل النشر / عند النشر / بعد النشر.
افتح القائمة المرجعية →
// step-by-step
كيفية تأمين تطبيق تم إنشاؤه باستخدام أدوات البرمجة AI
التعزيز خطوة بخطوة باستخدام مقتطفات التعليمات البرمجية. لماذا تفشل التطبيقات التي تم إنشاؤها AI- بشكل مختلف، وتدقيق قاعدة التعليمات البرمجية الفوري، وتعزيز وقت النشر (البرامج الوسيطة، CSP، RLS، مصادقة الخادم فقط)، والمراقبة المستمرة، وخمسة أنماط فشل حقيقية مع إصلاحاتها الفعلية.
ابدأ دليل التصلب →
// cursor-specific checklist
Cursor قائمة التحقق من أمان التطبيق
A 25-item hardening guide targeting Cursor-specific patterns: autocomplete inlines service keys, generated multi-file edits land without review, Agent mode runs terminal commands, and project rules (
.cursor/rules) are your first security guardrail. Pre-deploy, at-deploy, and post-deploy checks for Cursor workflows.اقرأ الدليل Cursor →
// tool-specific guides
Security checklists for Lovable, Bolt, v0, Replit, and Firebase Studio
A comprehensive pre-ship audit for founders launching AI-built SaaS. Covers customer data isolation, billing + Stripe, authentication + sessions, PII + compliance, operational readiness, external attack surface, observability, and final verification — 36 actionable items designed to complete in one week.
Browse the platform guides →
// structural analysis
لماذا تترك أدوات البرمجة AI فجوات أمنية
تحليل صادق للنقاط العمياء الهيكلية في Cursor وClaude Code وLovable وBolt وv0. يؤدي تحيز بيانات التدريب، وديناميكيات الإكمال التلقائي، وعدم وجود سياق طويل المدى، والسرعة كمقياس إلى خلق فجوات أمنية يمكن التنبؤ بها. تعرف على السبب الجذري لكل فئة فجوة ونمط العلاج الذي يغلقها.
قراءة تحليل الفجوة →
// scanner selection
اختيار ماسح ضوئي أمني لتطبيقات AI- المبنية
Comparison and decision framework for picking the right scanner — FixVibe, Burp Suite, ZAP, Snyk, Semgrep and Aikido. Covers the evaluation criteria that matter for AI-generated SaaS (BaaS coverage, JS bundle inspection, framework awareness, active-probe gating), a side-by-side table, and a decision matrix for six common scenarios.
قارن الماسحات الضوئية →
// قائمة تحقق المنصة
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations,
import.meta.envleaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.افتح قائمة التحقق →
// قائمة تحقق المنصة
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
افتح قائمة التحقق →
// قائمة تحقق المنصة
v0 security checklist: 22 items for Next.js
v0 generates React + Tailwind + shadcn/ui components and full Next.js apps for Vercel. This checklist targets v0-specific risks: design iterations that re-add dangerouslySetInnerHTML, exported codebases that lose middleware, Server Actions that skip auth verification, and environment variables that have to be set again once the code lives in your own repo. 22 items across secrets, database, auth, headers, deployment, and v0-specific gotchas.
افتح قائمة التحقق →
