Understanding the (In)Security of Vibe-Coded Applications

  • 类型:arxiv
  • 标识:2606.23130
  • 链接:http://arxiv.org/abs/2606.23130v1
  • 主分类:agent
  • 形态:application
  • 被引:0
  • 被引来源:Semantic Scholar + OpenAlex
  • S2被引:0
  • OpenAlex被引:0
  • 影响力被引:0
  • TLDR:This study collects a large corpus of real-world applications developed using popular AI agents and designs a vulnerability analysis framework that combines agent-assisted code auditing with human validation, and reveals recurring vulnerability patterns that differ from those commonly observed in conventional software development workflows.
  • OpenAlex ID:W7165616523
  • OpenAlex DOI:10.48550/arxiv.2606.23130
  • DOI:10.48550/arxiv.2606.23130
  • DOI来源:OpenAlex
  • 开放获取:green
  • 开放获取链接:https://doi.org/10.48550/arxiv.2606.23130
  • OpenAlex更新:2026-07-19
  • 待LLM分类:否
  • 标题中文:Understanding the (In)Security of Vibe-Coded Applications
  • TLDR中文:本研究收集了使用主流 AI Agent 开发的大量真实应用语料,并设计了结合 Agent 辅助代码审计与人工验证的漏洞分析框架,揭示出与传统软件开发流程中常见的漏洞模式不同的反复出现的漏洞规律。
  • 来源文件
  • /inbox/tom/_candidates/2026-06-23-agent-rag-longcontext-candidates.json
  • [S2 enrich]
  • [OpenAlex backfill]