Source transparency

Trace every major claim.

Peer-reviewed work, preprints, industry studies, standards, and journalism are not interchangeable. This index keeps those evidence tiers visible.

P

Peer-reviewed

Pearce et al. - Asleep at the Keyboard? (IEEE S&P 2022)

Security of Copilot-generated code. arXiv | IEEE

Perry et al. - Do Users Write More Insecure Code with AI Assistants? (ACM CCS 2023)

Human security behavior and confidence. arXiv

Fu et al. - Security Weaknesses of Copilot-Generated Code (ACM TOSEM 2025)

AI-generated snippets in real GitHub projects. ACM | arXiv

Vero et al. - BaxBench (ICML 2025)

Exploit-based backend benchmark. arXiv | Project

Spracklen et al. - We Have a Package for You! (USENIX Security 2025)

Package hallucination and slopsquatting risk. USENIX

Lee et al. - The Impact of Generative AI on Critical Thinking (CHI 2025)

Critical thinking in AI-assisted knowledge work. PDF

Peng et al. - The Impact of AI on Developer Productivity (2023)

Randomized controlled coding task. arXiv

Cui et al. - The Effects of Generative AI on High-Skilled Work (Management Science 2026)

Three enterprise field experiments. INFORMS

Fawzy et al. - Vibe Coding in Practice (ICSE-SEIP 2026)

Systematic review of practitioner accounts. ACM | arXiv

PP

Preprints

Deng, Fan & Meng - Understanding the (In)Security of Vibe-Coded Applications (2026)

The principal direct application audit and mitigation experiment. arXiv

Re-evaluating LLM Package Hallucinations (2026)

Frontier-model replication. arXiv

Kharma et al. - Code Security Across Prompting Methods (2026)

Security-aware prompting evaluation. arXiv

Guiding AI to Fix Its Own Flaws (2025)

Self-repair blind spots. arXiv

I

Industry research

DORA - State of AI-assisted Software Development (2025)

Adoption, throughput, stability, and organizational controls. Overview

Veracode - GenAI Code Security Reports (2025-2026)

Longitudinal functionality and security testing. Spring 2026

Stack Overflow Developer Survey (2025)

Adoption, trust, and developer frustrations. AI section

GitClear - The Maintainability Gap (2026)

Observational code-change trends; vendor-run and non-causal. Report

Anthropic - AI Assistance and Coding Skills (2026)

Randomized learning and comprehension experiment; vendor-run. Research

Standards

Guidance

NIST Secure Software Development Framework

Base SSDF controls apply to AI-generated code; SP 800-218A specifically concerns development of generative AI models. SP 800-218 | SP 800-218A

CSA Secure Vibe Coding Guide

Practical security guidance. CSA

GitHub Spec Kit

Spec-driven development framework; reasonable structural practice without direct efficacy data. GitHub

Incident records

Lovable row-level security exposure (2025)

Primary disclosure by Matt Palmer: a March 2025 scan found 303 endpoints across 170 projects, about 10.3% of the 1,645 analysed, readable without authentication. Catalogued as CVE-2025-48757, CVSS 9.3 Critical. The vendor disputes the record on shared-responsibility grounds. Disclosure statement | Technical write-up | NVD record

Replit production database deletion (2025)

Contemporaneous reporting on an agent executing a destructive command during a declared code freeze, then misreporting recoverability. Fortune

Tea app breach (2025)

Firebase misconfiguration exposing identity images and private messages. The breach is documented; claims that the application was vibe-coded remain unverified and are not treated as evidence here. Security.org