// docs / security guides
セキュリティガイド
Cursor、Claude Code、Lovable、Bolt、v0、Replit、Windsurf で構築されたアプリケーションを保護するための詳細なフレームワーク対応ガイド。各ガイドは独立して書かれています。現在行っていることに一致するものを選択してください。 FixVibe スキャン エンジンに新しい攻撃クラスが表示されると、さらに多くのガイドがここに表示されます。
// category overview
AI-生成されたコードのセキュリティ スキャン: バイブコード化されたアプリの DAST
AI-生成されたアプリに従来の侵入テスト ツールとは異なるスキャンが必要な理由。バイブコーディングされたアプリに不釣り合いに現れる 10 の脆弱性クラス、コードベースが半分機械生成されている場合の DAST と SAST、スキャナーで何を探すべきか、FixVibe と Burp Suite、OWASP ZAP、および Nessus との比較について説明します。
スキャナ入門を読む →
// pre-ship audit
バイブコーディングのセキュリティチェックリスト: 出荷前の 51 項目
Cursor、Claude Code、Lovable、Bolt を使用して構築されたアプリの実践的でフェーズ別のチェックリスト。 7 つのカテゴリ (シークレット、データベース、認証、ヘッダー、サードパーティ、デプロイメント、モニタリング) に 51 の実用的な項目があり、それぞれデプロイ前 / デプロイ時 / デプロイ後にタグ付けされています。
チェックリストを開く →
// step-by-step
AI コーディング ツールを使用して構築されたアプリを保護する方法
コードスニペットを使用した段階的な強化。 AI-生成されたアプリの失敗の仕方が異なる理由、即時のコードベース監査、デプロイ時の強化 (ミドルウェア、CSP、RLS、サーバーのみの認証)、継続的な監視、実際の修正を含む 5 つの実際の失敗パターン。
硬化ガイドを開始する →
// cursor-specific checklist
Cursor アプリのセキュリティ チェックリスト
A 25-item hardening guide targeting Cursor-specific patterns: autocomplete inlines service keys, generated multi-file edits land without review, Agent mode runs terminal commands, and project rules (
.cursor/rules) are your first security guardrail. Pre-deploy, at-deploy, and post-deploy checks for Cursor workflows.Cursor ガイドを読む →
// tool-specific guides
Security checklists for Lovable, Bolt, v0, Replit, and Firebase Studio
A comprehensive pre-ship audit for founders launching AI-built SaaS. Covers customer data isolation, billing + Stripe, authentication + sessions, PII + compliance, operational readiness, external attack surface, observability, and final verification — 36 actionable items designed to complete in one week.
Browse the platform guides →
// structural analysis
AI コーディング ツールがセキュリティ上のギャップを残す理由
Cursor、Claude Code、Lovable、Bolt、v0 の構造上の盲点を正直に分析しました。トレーニング データのバイアス、オートコンプリートのダイナミクス、長期的なコンテキストの欠如、およびメトリックとしての速度により、予測可能なセキュリティ ギャップが生じます。各ギャップ クラスの根本原因とそれを埋める修正パターンを学びます。
ギャップ分析を読む →
// scanner selection
AI-built アプリのセキュリティ スキャナーの選択
Comparison and decision framework for picking the right scanner — FixVibe, Burp Suite, ZAP, Snyk, Semgrep and Aikido. Covers the evaluation criteria that matter for AI-generated SaaS (BaaS coverage, JS bundle inspection, framework awareness, active-probe gating), a side-by-side table, and a decision matrix for six common scenarios.
スキャナーの比較 →
// プラットフォーム別チェックリスト
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations,
import.meta.envleaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.チェックリストを開く →
// プラットフォーム別チェックリスト
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
チェックリストを開く →
// プラットフォーム別チェックリスト
v0 security checklist: 22 items for Next.js
v0 generates React + Tailwind + shadcn/ui components and full Next.js apps for Vercel. This checklist targets v0-specific risks: design iterations that re-add dangerouslySetInnerHTML, exported codebases that lose middleware, Server Actions that skip auth verification, and environment variables that have to be set again once the code lives in your own repo. 22 items across secrets, database, auth, headers, deployment, and v0-specific gotchas.
チェックリストを開く →
