Vibe Coding and Web Application Security: A Twin-Prompt Study
Quick summary
arXiv:2608.20963v1 Announce Type: cross Abstract: Large language models increasingly generate complete web applications from natural-language prompts, raising the question of whether explicitly requesting security best practice improves the result. We study six functionally distinct web applications, each generated in two prompt variants that are identical except for an appended security-requirements section: a baseline (A) and a security-aware (B) variant. All twelve programs were produced by the same agentic coding assistant and the same model version in a single, non-iterative generation ro
Key takeaways
- arXiv:2608.20963v1 Announce Type: cross Abstract: Large language models increasingly generate complete web applications from natural-language prompts, raising the question of whether explicitly requesting security best practice improves the result.
- We study six functionally distinct web applications, each generated in two prompt variants that are identical except for an appended security-requirements section: a baseline (A) and a security-aware (B) variant.
- All twelve programs were produced by the same agentic coding assistant and the same model version in a single, non-iterative generation ro
Why it matters
“Vibe Coding and Web Application Security: A Twin-Prompt Study” shows why AI risk cannot be reduced to answer accuracy. Access controls, logging, human approval and incident response need to be designed into the workflow from the start.

Member comments