Source transparency
Trace every major claim.
Peer-reviewed work, preprints, industry studies, standards, and journalism are not interchangeable. This index keeps those evidence tiers visible.
Peer-reviewed
Perry et al. - Do Users Write More Insecure Code with AI Assistants? (ACM CCS 2023)
Human security behavior and confidence. arXiv
Fu et al. - Security Weaknesses of Copilot-Generated Code (ACM TOSEM 2025)
Vero et al. - BaxBench (ICML 2025)
Spracklen et al. - We Have a Package for You! (USENIX Security 2025)
Package hallucination and slopsquatting risk. USENIX
Lee et al. - The Impact of Generative AI on Critical Thinking (CHI 2025)
Critical thinking in AI-assisted knowledge work. PDF
Peng et al. - The Impact of AI on Developer Productivity (2023)
Randomized controlled coding task. arXiv
Cui et al. - The Effects of Generative AI on High-Skilled Work (Management Science 2026)
Three enterprise field experiments. INFORMS
Fawzy et al. - Vibe Coding in Practice (ICSE-SEIP 2026)
Preprints
Deng, Fan & Meng - Understanding the (In)Security of Vibe-Coded Applications (2026)
The principal direct application audit and mitigation experiment. arXiv
METR - Measuring the Impact of Early-2025 AI (2025)
Experienced open-source maintainers. arXiv | Follow-up limitations
Re-evaluating LLM Package Hallucinations (2026)
Frontier-model replication. arXiv
Kharma et al. - Code Security Across Prompting Methods (2026)
Security-aware prompting evaluation. arXiv
Guiding AI to Fix Its Own Flaws (2025)
Self-repair blind spots. arXiv
Industry research
DORA - State of AI-assisted Software Development (2025)
Adoption, throughput, stability, and organizational controls. Overview
Veracode - GenAI Code Security Reports (2025-2026)
Longitudinal functionality and security testing. Spring 2026
Stack Overflow Developer Survey (2025)
Adoption, trust, and developer frustrations. AI section
GitClear - The Maintainability Gap (2026)
Observational code-change trends; vendor-run and non-causal. Report
Anthropic - AI Assistance and Coding Skills (2026)
Randomized learning and comprehension experiment; vendor-run. Research
Guidance
NIST Secure Software Development Framework
Base SSDF controls apply to AI-generated code; SP 800-218A specifically concerns development of generative AI models. SP 800-218 | SP 800-218A
CSA Secure Vibe Coding Guide
Practical security guidance. CSA
GitHub Spec Kit
Spec-driven development framework; reasonable structural practice without direct efficacy data. GitHub
Incident records
Lovable row-level security exposure (2025)
Primary disclosure by Matt Palmer: a March 2025 scan found 303 endpoints across 170 projects, about 10.3% of the 1,645 analysed, readable without authentication. Catalogued as CVE-2025-48757, CVSS 9.3 Critical. The vendor disputes the record on shared-responsibility grounds. Disclosure statement | Technical write-up | NVD record
Replit production database deletion (2025)
Contemporaneous reporting on an agent executing a destructive command during a declared code freeze, then misreporting recoverability. Fortune
Tea app breach (2025)
Firebase misconfiguration exposing identity images and private messages. The breach is documented; claims that the application was vibe-coded remain unverified and are not treated as evidence here. Security.org