VibeCoded

Can AI fix its own security bugs?

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Partly. Given a specific finding with reproduction steps, AI tools fix most issues well. Asked vaguely to "make the app secure", they change some things and report success without verifying anything. They also cannot find what they do not know is missing. Use the AI to apply fixes from a test report, then have a person confirm each fix actually closed the hole.

Where it works

  • Applying a specific fix: "the /api/orders/:id endpoint returns orders for any user; restrict it to the owner".
  • Adding row level security policies when told which tables and rules.
  • Moving a key from the front end to a server function.
  • Writing a test that proves user A cannot read user B's data.

Where it fails

  • Finding the gaps in the first place: it reviews code with the assumptions that produced it.
  • Verifying: it reports a fix as done when a second route still has the hole.
  • Rotating secrets: removing a leaked key from code does not revoke it.
  • Business rules it was never told, such as which role may refund.

The workflow that works

  1. Get findings from a test, with reproduction steps.
  2. Paste one finding at a time into your AI tool.
  3. Ask for the fix and a test proving it.
  4. Reproduce the original steps yourself.
  5. Ask the tester to retest. See retests.

Verifying a fix yourself

For each fix, rerun the exact steps from the finding: the same request, with the same accounts. Then try neighbouring cases: the same record type through a different endpoint, a different record type through the same endpoint, and the same action with no session at all. AI fixes are often narrow, closing the precise example reported while a sibling route keeps the hole.

Ask the AI to search the whole codebase for the same pattern and list every place it applies, then check the list. Finally, keep a test that reproduces the original finding and fails if it reopens. That test is what protects you the next time the tool regenerates the feature.

Getting it checked

TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.

Get a scope for your app

Tell us what you built, what it stores and who is about to use it.

Get matched

Common questions

Should I ask the AI to do a security review first?

Yes, it is free and catches some issues. Treat it as a checklist pass, not an independent test.

Why does it say the fix is done when it is not?

It checks that the code it changed looks right. It does not attack the running app to prove the hole is closed.