Vibe Coding Security
Case study · Tech & fun
Dated advisories on software supply-chain attacks, malicious MCP servers and prompt injection, with affected-version checks, recovery playbooks and prevention guides.
- What
- Dated advisories on software supply-chain attacks, malicious MCP servers and prompt injection, with affected-version checks, recovery playbooks and prevention guides.
- Stack
- Markdown advisories rendered by a Python build; a pytest suite gates every deploy.
- Status
- LIVE
- Dates
- Scope reviewed October 2, 2026; data dates shown in the app
- Links
- Live site · Source code
Background
Which incidents affect people building with AI coding tools?
The tracker collects software supply-chain incidents, malicious MCP servers, prompt-injection campaigns and credential theft. Dated advisories identify affected ecosystems and link to disclosures, investigations and recovery guidance.
A Look Inside
Each view shown on mobile and desktop — tap any image to open the live site.
How It Works
- Advisories: Each incident has dates, severity, status, source links and an affected-version or exposure check.
- Recovery: Playbooks distinguish investigation, credential rotation and restoration steps.
- Prevention: Guides cover dependency and agent-tool risks with actionable controls.
- Publishing: Structured Markdown builds into the static site, advisory index, JSON and Atom feed.
- Freshness: Recorded update dates show when an advisory was reviewed; source reports can evolve.
Scope reviewed October 2, 2026 · Project documentation. Source data keeps its published dates.



