Skip to content
LyraShield AIOpen beta

Coverage contract · vibe-security-50/1.1.0

The Vibe Security 50

A fixed list of 50 security controls LyraShield AI reviews on AI-built applications. 43 are routed to deterministic, hybrid, or agentic code/URL review where applicable. The remaining 7 describe operational practice that a repository or URL scan cannot establish safely, so they ask you for evidence instead of guessing.

This page is generated from the same registry the scanner executes, so the list below and the counts quoted elsewhere on this site cannot drift apart. Last reviewed: .

What a result does and does not say

Detected
Evidence was returned for the control.
No finding returned
The assigned check completed without reporting anything in scope. A no-finding result is not independent verification, and LyraShield never shows it as passed.
Inconclusive
The control applied, but the available scan could not establish an outcome.
Not applicable
The control does not apply to the scanned target type or available subject.

Automated check5 of 50

A bounded, repeatable check over your repository or public surface. Same input, same answer.

  1. Secrets and privileged keys exposed in frontend bundles

  2. Missing security headers

  3. Weak transport security

  4. Vulnerable or outdated dependencies

  5. Poisoned rules and instruction files

Automated signal, reviewed for exploitability10 of 50

An automated signal finds the pattern; establishing whether it is actually exploitable in your app needs review.

  1. Missing database row-level security

  2. IDOR / broken object-level authorization

  3. Permissive CORS

  4. OAuth redirect and callback mistakes

  5. Insecure cookies

  6. Verbose errors and debug endpoints

  7. Source maps and build-artifact leakage

  8. Hallucinated or malicious packages

  9. Unsafe install scripts and dependency supply chain

  10. CI/CD confused deputy

Agentic review28 of 50

Requires authentication, data-flow reasoning, live interaction, or business context, so an agent works through it.

  1. Client-side-only authentication

  2. Missing server-side authorization

  3. Cross-tenant data leakage

  4. Unprotected admin and internal routes

  5. Broken JWT and session validation

  6. Password reset and email-verification flaws

  7. Unsafe password storage

  8. SQL injection

  9. Cross-site scripting

  10. Missing input validation

  11. Missing CSRF protection

  12. Server-side request forgery

  13. Unsafe file uploads

  14. Path traversal

  15. Command injection

  16. Missing rate limits

  17. Brute force and account enumeration

  18. Unverified Stripe webhooks

  19. Payment and entitlement logic bypass

  20. Mass assignment

  21. Replay, race, and idempotency failures

  22. Public-by-default apps, buckets, and databases

  23. Sensitive data in logs and analytics

  24. Secrets leaked through AI prompts and context

  25. Indirect prompt injection

  26. Over-permissioned MCP tools

  27. Destructive production permissions

  28. Placeholder logic and silent business failures

Requires evidence outside the scan7 of 50

Cannot be established safely from a repository or URL scan. It needs accountable operational or human review outside the current scan.

  1. Missing audit trails

  2. Missing monitoring and alerts

  3. Missing backup and recovery proof

  4. Missing agent sandbox and egress controls

  5. AI-generated test fabrication and blind spots

  6. Multi-agent propagation

  7. No accountable human review or threat model

Common questions

What is the Vibe Security 50?

It is a fixed list of 50 security controls that LyraShield AI reviews on AI-built applications. 43 enter deterministic, hybrid, or engine-led review where applicable, while 7 require evidence a scan cannot establish on its own. The list is versioned as vibe-security-50/1.1.0.

Does a clean result mean my app is secure?

No. When a check completes without returning a finding, that is recorded as no finding returned — not as passed. It means the assigned check ran and reported nothing within its scope, which is narrower than a statement about your whole application.

Why can't all 50 controls be automated?

Seven of them describe operational practice rather than code: audit coverage, monitoring, restore proof, deployment egress, test independence, multi-agent trust, and accountable review. A repository or URL scan cannot observe those safely, so they remain outside-scan evidence requirements instead of guessed results.

Does every scan check all 50 controls?

No, and the record says which. Applicability depends on the target: a URL or API scan cannot exercise repository or operational controls, and each control gets a receipt recording whether it completed, was limited, did not apply, or still needs evidence.

Where is evidence for the 7 operational controls stored?

In the LyraShield Operational Evidence Vault. Each workspace keeps its own encrypted, versioned evidence behind row-level security. Accepted evidence is frozen into private assurance reports; shared public reports do not include it.

See it against your own app

The free Lite Check runs the passive public-surface subset with no account. A full review routes applicable controls through the available review methods and records a receipt for every one of the 50.