Vibe coding has significantly accelerated software prototyping but AI
agents frequently recommend insecure configurations, creating security
problems. Gautam Koul, Lucian Moss, Neil Drew-Lopez, and Daberechi
Ruth Edeokoh share their experience while building applications
for Thoughtworks’s global marketing. They learned that to combat this we
need to write a security context file to guide the AI, be cautious with AI
permission requests, create a daily security intelligence feed, and
provide builders with a secure-by-default harness and templates.
