// docs / security guides
安全指南
深入的框架感知指南,用于保护使用 Cursor、Claude Code、Lovable、Bolt、v0、Replit 和 Windsurf 构建的应用程序。每份指南都是独立编写的 - 选择与您现在正在做的事情相匹配的指南。随着 FixVibe 扫描引擎中出现新的攻击类别,更多指南将在此发布。
// category overview
AI-生成的代码安全扫描:DAST 用于vibe编码的应用程序
为什么AI-生成的应用程序需要与传统渗透测试工具不同的扫描。涵盖了在vibe编码的应用程序中不成比例地出现的十个漏洞类别,当代码库是半机器生成时的DAST与SAST,在扫描仪中查找什么,以及FixVibe如何与Burp Suite、OWASP ZAP和Nessus进行比较。
阅读扫描仪底漆 →
// pre-ship audit
vivi 编码安全检查表:发货前的 51 项
针对使用Cursor、Claude Code、Lovable 和Bolt 构建的应用程序的实用的、分阶段组织的清单。七个类别——秘密、数据库、身份验证、标头、第三方、部署、监控——有 51 个可操作的项目,每个项目都标记为部署前/部署时/部署后。
打开清单 →
// step-by-step
如何保护使用 AI 编码工具构建的应用程序
使用代码片段逐步强化。为什么AI-生成的应用程序会以不同的方式失败,立即代码库审核,部署时强化(中间件,CSP,RLS,仅服务器身份验证),持续监控以及五种真实的故障模式及其实际修复。
启动强化指南 →
// cursor-specific checklist
Cursor 应用程序安全检查表
A 25-item hardening guide targeting Cursor-specific patterns: autocomplete inlines service keys, generated multi-file edits land without review, Agent mode runs terminal commands, and project rules (
.cursor/rules) are your first security guardrail. Pre-deploy, at-deploy, and post-deploy checks for Cursor workflows.阅读Cursor指南 →
// tool-specific guides
Security checklists for Lovable, Bolt, v0, Replit, and Firebase Studio
A comprehensive pre-ship audit for founders launching AI-built SaaS. Covers customer data isolation, billing + Stripe, authentication + sessions, PII + compliance, operational readiness, external attack surface, observability, and final verification — 36 actionable items designed to complete in one week.
Browse the platform guides →
// structural analysis
为什么AI编码工具会留下安全漏洞
对Cursor、Claude Code、Lovable、Bolt 和 v0 中结构盲点的诚实分析。训练数据偏差、自动完成动态、没有长期上下文以及速度指标会造成可预测的安全漏洞。了解每个差距类别的根本原因以及消除该差距的补救模式。
阅读差距分析 →
// scanner selection
为AI-构建的应用程序选择安全扫描仪
Comparison and decision framework for picking the right scanner — FixVibe, Burp Suite, ZAP, Snyk, Semgrep and Aikido. Covers the evaluation criteria that matter for AI-generated SaaS (BaaS coverage, JS bundle inspection, framework awareness, active-probe gating), a side-by-side table, and a decision matrix for six common scenarios.
比较扫描仪 →
// 平台检查清单
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations,
import.meta.envleaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.打开检查清单 →
// 平台检查清单
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
打开检查清单 →
// 平台检查清单
v0 security checklist: 22 items for Next.js
v0 generates React + Tailwind + shadcn/ui components and full Next.js apps for Vercel. This checklist targets v0-specific risks: design iterations that re-add dangerouslySetInnerHTML, exported codebases that lose middleware, Server Actions that skip auth verification, and environment variables that have to be set again once the code lives in your own repo. 22 items across secrets, database, auth, headers, deployment, and v0-specific gotchas.
打开检查清单 →
