// docs / security guides
安全指南
深入的框架感知指南,用於保護使用 Cursor、Claude Code、Lovable、Bolt、v0、Replit 和 Windsurf 建立的應用程式。每份指南都是獨立編寫的 - 選擇與您現在正在做的事情相符的指南。隨著 FixVibe 掃描引擎中出現新的攻擊類別,更多指南將在此發布。
// category overview
AI-產生的代碼安全掃描:DAST 用於vibe編碼的應用程式
為什麼AI-產生的應用程式需要與傳統滲透測試工具不同的掃描。涵蓋了在vibe編碼的應用程式中不成比例地出現的十個漏洞類別,當代碼庫是半機器生成時的DAST與SAST,在掃描器中查找什麼,以及FixVibe如何與Burp Suite、OWASP ZAP和Nessus進行比較。
閱讀掃描器底漆 →
// pre-ship audit
vivi 編碼安全檢查表:出貨前的 51 項
針對使用Cursor、Claude Code、Lovable 和Bolt 建立的應用程式的實用的、分階段組織的清單。七個類別——秘密、資料庫、身份驗證、標頭、第三方、部署、監控——有 51 個可操作的項目,每個項目都標記為部署前/部署時/部署後。
開啟清單 →
// step-by-step
如何保護使用 AI 編碼工具建立的應用程式
使用程式碼片段逐步強化。為什麼AI-生成的應用程式會以不同的方式失敗,立即代碼庫審核,部署時強化(中間件,CSP,RLS,僅伺服器身份驗證),持續監控以及五種真實的故障模式及其實際修復。
啟動強化指南 →
// cursor-specific checklist
Cursor 應用程式安全檢查表
A 25-item hardening guide targeting Cursor-specific patterns: autocomplete inlines service keys, generated multi-file edits land without review, Agent mode runs terminal commands, and project rules (
.cursor/rules) are your first security guardrail. Pre-deploy, at-deploy, and post-deploy checks for Cursor workflows.閱讀Cursor指南 →
// tool-specific guides
Security checklists for Lovable, Bolt, v0, Replit, and Firebase Studio
A comprehensive pre-ship audit for founders launching AI-built SaaS. Covers customer data isolation, billing + Stripe, authentication + sessions, PII + compliance, operational readiness, external attack surface, observability, and final verification — 36 actionable items designed to complete in one week.
Browse the platform guides →
// structural analysis
為什麼AI編碼工具會留下安全漏洞
對Cursor、Claude Code、Lovable、Bolt 和 v0 中結構盲點的誠實分析。訓練資料偏差、自動完成動態、沒有長期情境以及速度指標會造成可預測的安全漏洞。了解每個差距類別的根本原因以及消除該差距的補救模式。
閱讀差距分析 →
// scanner selection
為AI-建置的應用程式選擇安全掃描儀
Comparison and decision framework for picking the right scanner — FixVibe, Burp Suite, ZAP, Snyk, Semgrep and Aikido. Covers the evaluation criteria that matter for AI-generated SaaS (BaaS coverage, JS bundle inspection, framework awareness, active-probe gating), a side-by-side table, and a decision matrix for six common scenarios.
比較掃描儀 →
// 平台檢查清單
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations,
import.meta.envleaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.開啟檢查清單 →
// 平台檢查清單
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
開啟檢查清單 →
// 平台檢查清單
v0 security checklist: 22 items for Next.js
v0 generates React + Tailwind + shadcn/ui components and full Next.js apps for Vercel. This checklist targets v0-specific risks: design iterations that re-add dangerouslySetInnerHTML, exported codebases that lose middleware, Server Actions that skip auth verification, and environment variables that have to be set again once the code lives in your own repo. 22 items across secrets, database, auth, headers, deployment, and v0-specific gotchas.
開啟檢查清單 →
