Coverage contract · vibe-security-50/1.1.0
The Vibe Security 50
A fixed list of 50 security controls LyraShield AI reviews on AI-built applications. 43 are routed to deterministic, hybrid, or agentic code/URL review where applicable. The remaining 7 describe operational practice that a repository or URL scan cannot establish safely, so they ask you for evidence instead of guessing.
This page is generated from the same registry the scanner executes, so the list below and the counts quoted elsewhere on this site cannot drift apart. Last reviewed: .
What a result does and does not say
- Detected
- Evidence was returned for the control.
- No finding returned
- The assigned check completed without reporting anything in scope. A no-finding result is not independent verification, and LyraShield never shows it as passed.
- Inconclusive
- The control applied, but the available scan could not establish an outcome.
- Not applicable
- The control does not apply to the scanned target type or available subject.
Automated check5 of 50
A bounded, repeatable check over your repository or public surface. Same input, same answer.
Secrets and privileged keys exposed in frontend bundles
Missing security headers
Weak transport security
Vulnerable or outdated dependencies
Poisoned rules and instruction files
Automated signal, reviewed for exploitability10 of 50
An automated signal finds the pattern; establishing whether it is actually exploitable in your app needs review.
Missing database row-level security
IDOR / broken object-level authorization
Permissive CORS
OAuth redirect and callback mistakes
Insecure cookies
Verbose errors and debug endpoints
Source maps and build-artifact leakage
Hallucinated or malicious packages
Unsafe install scripts and dependency supply chain
CI/CD confused deputy
Agentic review28 of 50
Requires authentication, data-flow reasoning, live interaction, or business context, so an agent works through it.
Client-side-only authentication
Missing server-side authorization
Cross-tenant data leakage
Unprotected admin and internal routes
Broken JWT and session validation
Password reset and email-verification flaws
Unsafe password storage
SQL injection
Cross-site scripting
Missing input validation
Missing CSRF protection
Server-side request forgery
Unsafe file uploads
Path traversal
Command injection
Missing rate limits
Brute force and account enumeration
Unverified Stripe webhooks
Payment and entitlement logic bypass
Mass assignment
Replay, race, and idempotency failures
Public-by-default apps, buckets, and databases
Sensitive data in logs and analytics
Secrets leaked through AI prompts and context
Indirect prompt injection
Over-permissioned MCP tools
Destructive production permissions
Placeholder logic and silent business failures
Requires evidence outside the scan7 of 50
Cannot be established safely from a repository or URL scan. It needs accountable operational or human review outside the current scan.
Missing audit trails
Missing monitoring and alerts
Missing backup and recovery proof
Missing agent sandbox and egress controls
AI-generated test fabrication and blind spots
Multi-agent propagation
No accountable human review or threat model
Common questions
What is the Vibe Security 50?
It is a fixed list of 50 security controls that LyraShield AI reviews on AI-built applications. 43 enter deterministic, hybrid, or engine-led review where applicable, while 7 require evidence a scan cannot establish on its own. The list is versioned as vibe-security-50/1.1.0.
Does a clean result mean my app is secure?
No. When a check completes without returning a finding, that is recorded as no finding returned — not as passed. It means the assigned check ran and reported nothing within its scope, which is narrower than a statement about your whole application.
Why can't all 50 controls be automated?
Seven of them describe operational practice rather than code: audit coverage, monitoring, restore proof, deployment egress, test independence, multi-agent trust, and accountable review. A repository or URL scan cannot observe those safely, so they remain outside-scan evidence requirements instead of guessed results.
Does every scan check all 50 controls?
No, and the record says which. Applicability depends on the target: a URL or API scan cannot exercise repository or operational controls, and each control gets a receipt recording whether it completed, was limited, did not apply, or still needs evidence.
Where is evidence for the 7 operational controls stored?
In the LyraShield Operational Evidence Vault. Each workspace keeps its own encrypted, versioned evidence behind row-level security. Accepted evidence is frozen into private assurance reports; shared public reports do not include it.
See it against your own app
The free Lite Check runs the passive public-surface subset with no account. A full review routes applicable controls through the available review methods and records a receipt for every one of the 50.