You can now tell a coding agent:
Build a to-do app with login, categories and search.
Keep the interface simple and deploy it when it works.
A usable website may appear surprisingly quickly.
This style of development—describing desired outcomes in natural language while AI generates and modifies much of the code—is often called vibe coding.
Its biggest strength is also the source of a common misconception:
A screen that runs is not automatically finished software.
Prototype and production have different goals
A prototype is designed to test an idea quickly: does the flow feel useful, does the interface make sense, will anyone want the product?
Vibe coding is extremely effective here.
A production system must also handle permissions, data consistency, error recovery, backups, monitoring, security, migrations, scaling and dependency updates.
Most of those problems are invisible in a beautiful landing-page demo.
The dangerous gap is what you do not know to inspect
An agent might generate:
const isAdmin = localStorage.getItem('role') === 'admin';
A beginner may see an “admin check” and assume authorization is handled. But a value stored only in the browser can potentially be modified by the user.
The problem is not that AI always writes insecure code. The problem is that a user without the relevant background may not recognize when a plausible-looking design is unsafe.
Vibe coding is excellent for low-risk projects
Good starting points include:
- personal tools,
- landing pages,
- prototypes,
- low-risk internal workflows,
- data-visualization demos,
- one-off scripts.
In these cases, learning and iteration speed may matter more than five years of maintenance.
Raise the bar when the app touches real risk
Be much more careful around:
- authentication,
- payments,
- personal data,
- medical data,
- company secrets,
- production databases,
- file uploads,
- arbitrary code execution.
These need more than “I clicked around and it worked.”
Vibe coding and coding agents are related but not identical
Lesson 048 describes what a coding agent can do: inspect a repository, edit, test and open a PR.
Vibe coding describes more of the human workflow. One person may delegate almost everything and avoid reading code. Another may use the same agent aggressively while reviewing every architectural change.
The risk profile is very different.
Four things every beginner should learn to inspect
1. Git diff
Lesson 027 introduced Git. You do not need to understand every line, but you should know what files changed, what was deleted and what dependencies appeared.
2. Tests
Ask the agent to add and actually run tests. A statement that “the tests should pass” is not evidence that they did.
3. Secrets
Do not hard-code API keys into browser code or commit them to a repository.
4. Database migrations
Schema changes and destructive data operations need backups, review and a rollback plan.
The strongest workflow still has a human boundary
A practical pattern is:
Human defines requirements and acceptance criteria
AI implements much of the work
Automated tests check repeatable behavior
Human reviews important design and risk
You do not need to type every line yourself, but you should understand the boundaries that can lose money, data or trust.
One thing to remember
Vibe coding can compress the path from idea to prototype dramatically. Once the software handles accounts, money, secrets or long-lived data, testing, version control, security review and engineering judgment are still required.
Comments
Questions, reactions and useful additions are welcome here.
No comments yet. Be the 1F.