top | item 46448291

(no title)

akhnid | 2 months ago

I haven't said that the app is fully vibe coded, i said we used AI. The app is not fully vibecoded but we have used AI assistance and i am aware of the security concerns that comes with github/ slack implementation. Its a question of how you use AI in your app the system is fully designed by us so we know how it exactly behaves and how the data and tokens are stored/ exchanged.

discuss

order

manchicken|2 months ago

You mention tokens, what else is in your threat model? Is your AI functionality a custom model?

I am concerned that you haven’t adequately explored and mitigated security and reliability risks involved here before asking folks to YOLO your app into their critical infrastructure.