FlawPilot
The FlawPilot blog

Ship fast without shipping the vulnerabilities

Field notes on securing AI-generated apps - security headers, DMARC, TLS, performance, and the gaps that ship silently when you build in days instead of months.

7 articles

SecurityLatest

Replit App Security: What's Missing by Default

A public Repl doesn't just expose your app, it can expose your source and hardcoded secrets to anyone with the URL. Here's the checklist most builders skip.

ReplitReplit AgentAI-generated code+3
27 Jul 20269 min readRead
Security

Bolt.new App Security: What's Missing by Default

Bolt.new wires up Supabase in seconds, but Row-Level Security, headers, and DNS records still aren't set. The security checklist most builders skip.

Bolt.newAI-generated codeapplication security+3
24 Jul 20269 min readRead
Security

v0 App Security: What's Missing by Default

v0 ships clean React and Next.js code fast, but one misplaced NEXT_PUBLIC_ variable can leak a secret key straight to the browser. Here's the checklist.

v0VercelAI-generated code+3
22 Jul 20269 min readRead
Infrastructure

FlawPilot MCP Server & API: Coming Next Week

FlawPilot's MCP server and public API launch next week - scan from Claude Code or Cursor, or call the API directly. Here's what's coming and why it matters.

MCPModel Context ProtocolAPI+3
20 Jul 20266 min readRead
Security

Lovable App Security: A Real App, 29 Issues Found

Lovable app security, tested on a real app: a Supabase table with no Row-Level Security, wide open to anyone. Here's exactly what we found and how to fix it.

LovableAI-generated codeSupabase+2
17 Jul 20269 min readRead
Security

Cursor App Security: What's Missing by Default

Cursor writes fast, production-ready code, but headers, TLS, and DNS records still need manual setup. The cursor app security checklist most builders skip.

CursorAI-generated codesecurity headers+2
15 Jul 20268 min readRead