Mihály Tari.

FREE SELF-CHECK

How risky is your AI-written code?

In my experience a few questions quickly show where AI-written code goes wrong. These thirteen are what I check first in an audit. Each is a yes or no, and not knowing is an answer too. At the end you get a score and your three most serious risks.

13 questions · 2 minutes · nothing is stored

Are you certain no API key or password is left in an earlier version of the code, or in the code that ships to the browser?
On every endpoint that changes data — the addresses your app reads and writes through — does the server check that the caller is allowed to make it, rather than the screen just hiding the button?
If you have two customers, does the database itself guarantee that neither can read the other's rows?
Does the server check every user input before it reaches a query, a command, a template or a prompt?
Is there a database backup that someone has actually restored from?
Are the endpoints that call an AI, send email or handle sign-ups limited in how often they can be called, so nobody can run your card dry?
If an existing feature breaks, does any test fail?
Has someone read the login, payment and data-handling code end to end, rather than just accepting the AI's output?
Does anything tell you when a dependency has a known vulnerability?
Do you hear about a production error before the user tells you?
Are login, password storage and sessions handled by a proven library or service, rather than by code an AI wrote for you?
Do only the people who need them have production keys and release access, and do all of them use two-factor authentication?
Is the database shut off from the public internet, so that it can only be reached from your own server or through the provider's access controls?