// docs / security guides
보안 가이드
Cursor, Claude Code, Lovable, Bolt, v0, Replit 및 Windsurf로 구축된 애플리케이션 보안을 위한 심층적인 프레임워크 인식 가이드입니다. 각 가이드는 독립적으로 작성되었습니다. 현재 수행 중인 작업과 일치하는 가이드를 선택하세요. FixVibe 스캔 엔진에 새로운 공격 클래스가 나타나면서 더 많은 가이드가 여기에 표시됩니다.
// category overview
AI- 생성된 코드 보안 스캐닝: DAST 바이브 코딩 앱용
AI- 생성된 앱은 기존 침투 테스트 도구와 다른 검사가 필요한 이유 바이브 코딩된 앱에서 불균형적으로 나타나는 10가지 취약성 클래스, DAST 대 SAST(코드베이스가 절반 기계 생성인 경우), 스캐너에서 찾아야 할 사항, FixVibe을 Burp Suite, OWASPZAP 및 Nessus와 비교하는 방법을 다룹니다.
스캐너 입문서 읽기 →
// pre-ship audit
바이브 코딩 보안 체크리스트: 배송 전 51개 항목
Cursor, Claude Code, Lovable 및 Bolt으로 구축된 앱을 위한 실용적이고 단계별로 구성된 체크리스트입니다. 비밀, 데이터베이스, 인증, 헤더, 타사, 배포, 모니터링 등 7개 범주에는 실행 가능한 항목 51개가 포함되어 있으며 각각 사전 배포/배포 시/배포 후 태그가 지정되어 있습니다.
체크리스트 열기 →
// step-by-step
AI 코딩 도구로 구축된 앱을 보호하는 방법
코드 조각을 사용한 단계별 강화. AI- 생성된 앱이 다르게 실패하는 이유, 즉각적인 코드베이스 감사, 배포 시간 강화(미들웨어, CSP, RLS, 서버 전용 인증), 지속적인 모니터링, 실제 수정 사항이 포함된 5가지 실제 실패 패턴.
강화 가이드 시작 →
// cursor-specific checklist
Cursor 앱 보안 체크리스트
A 25-item hardening guide targeting Cursor-specific patterns: autocomplete inlines service keys, generated multi-file edits land without review, Agent mode runs terminal commands, and project rules (
.cursor/rules) are your first security guardrail. Pre-deploy, at-deploy, and post-deploy checks for Cursor workflows.Cursor 가이드 읽기 →
// tool-specific guides
Security checklists for Lovable, Bolt, v0, Replit, and Firebase Studio
A comprehensive pre-ship audit for founders launching AI-built SaaS. Covers customer data isolation, billing + Stripe, authentication + sessions, PII + compliance, operational readiness, external attack surface, observability, and final verification — 36 actionable items designed to complete in one week.
Browse the platform guides →
// structural analysis
AI 코딩 도구가 보안 공백을 남기는 이유
Cursor, Claude Code, Lovable, Bolt 및 v0의 구조적 맹점에 대한 정직한 분석입니다. 훈련 데이터 편향, 자동 완성 역학, 장기적인 맥락 없음, 측정 기준 속도로 인해 예측 가능한 보안 격차가 발생합니다. 각 격차 클래스의 근본 원인과 이를 해소하는 수정 패턴을 알아보세요.
격차 분석 읽기 →
// scanner selection
AI-빌드된 앱을 위한 보안 스캐너 선택
Comparison and decision framework for picking the right scanner — FixVibe, Burp Suite, ZAP, Snyk, Semgrep and Aikido. Covers the evaluation criteria that matter for AI-generated SaaS (BaaS coverage, JS bundle inspection, framework awareness, active-probe gating), a side-by-side table, and a decision matrix for six common scenarios.
스캐너 비교 →
// 플랫폼 체크리스트
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations,
import.meta.envleaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.체크리스트 열기 →
// 플랫폼 체크리스트
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
체크리스트 열기 →
// 플랫폼 체크리스트
v0 security checklist: 22 items for Next.js
v0 generates React + Tailwind + shadcn/ui components and full Next.js apps for Vercel. This checklist targets v0-specific risks: design iterations that re-add dangerouslySetInnerHTML, exported codebases that lose middleware, Server Actions that skip auth verification, and environment variables that have to be set again once the code lives in your own repo. 22 items across secrets, database, auth, headers, deployment, and v0-specific gotchas.
체크리스트 열기 →
