──[ ▮ ]── blog
Field notes on shipping AI-built apps safely
The mistakes Claude Code, Cursor and Codex make most — and how to catch them with a deterministic, local gate before they reach production.
vibe
Vibe Coding Security: 12 Checks Before You Ship
supabase-firebase
Supabase RLS: The Security Check Every AI-Built App Skips
secrets
What a Real Secret Scan Found in a Vibe-Coded App
secrets
Secret Scanner for Next.js + Supabase Apps: Scan Before You Deploy
secrets
GitHub Secret Scanner vs CLI Tools: gitleaks, TruffleHog, and ShipGuard Compared
supabase-firebase
Firebase Security Rules: The Test-Mode Trap That Exposes Your Database
tool-harness
Is Claude Code's Output Secure? I Audited What It Generates
shipguard · secrets