OpenSSF Finding and Fixing Vulnerabilities Using AI

6.1 Limit vibe coding

The practice of using AI to generate code and not having a human review the results is called vibe coding. If the results are important for security, don’t do that.

Modern AI has become far better at generating code. However, AI often generates insecure code. If the code can’t have a security impact (e.g., it doesn’t process untrusted input), vibe coding may be fine. However, if its failures may cause serious problems, don’t accept AI-generated code without review.

The increased use of vibe coding in security-relevant code has led to an explosion in the number of vulnerable code releases. “Researchers at Georgia Tech’s Vibe Security Radar tracked CVEs directly attributable to AI coding tools and found that March 2026 alone produced more than all of 2025 combined.” [Holterhoff2026]

Stay skeptical. In a controlled study, participants with access to an AI assistant “wrote significantly less secure code than those without access” yet “were more likely to believe they wrote secure code” [Perry2023]. Participants who trusted the AI less and worked more on their prompts produced code with fewer vulnerabilities.

You can reduce the number of vulnerabilities AI code assistants generate in the first place by giving them security-focused instructions; see the OpenSSF “Security-Focused Guide for AI Code Assistant Instructions” [OpenSSF2025-AIInstructions].

Where security matters, you need to have AI look for vulnerabilities and then have human review of that AI-generated code. You can use AI to generate code! Generating code with AI, especially code that doesn’t process untrusted inputs and doesn’t need good performance, can save time. The problem arises if you unwisely believe that AI-generated code never has defects or vulnerabilities.

Someday this review may no longer be necessary, or perhaps it can be completely automated. We can’t predict how good AI will get over time, or at what rate. However, at the time of this writing, human review is necessary if failures can cause serious problems.

Quiz

Q1. What does the material warn about unreviewed AI-generated code (“vibe coding”)?

  1. It’s inherently more secure than any human-written code
  2. It can’t be reviewed by any automated tool at all
  3. It often introduces vulnerabilities, so it needs scanning plus human review
  4. Most major open source projects have banned all AI-generated results in all cases
Show answer Answer: C