Vibe coding is leaking enterprise secrets to GitHub

red padlock on black computer keyboard

Vibe coding is producing real software fast. It is also producing real security incidents. Analysts at Gartner and Forrester, along with researchers from three universities, are flagging the same root problem: non-developers shipping apps without security reviews are exposing credentials and internal data to the public internet.

The Specific Threat

Pete Shoard, Gartner’s chief of research for cybersecurity, named the top risk directly: hard-coded secrets inside vibe-coded applications getting pushed to public GitHub repositories. Once a credential lands in a public repo, it is a route in. The problem compounds because enterprises are encouraging non-technical employees to build apps, and most of those apps will never be scanned.

“Vibe coding makes writing apps more accessible to teams that don’t have developer or security experience, which expands the enterprise attack surface,” said Erik Nost, senior security analyst at Forrester Research.

a white dice with a black github logo on it

What the Research Says

Researchers from Massey University and the University of Auckland found that 62% of vibe coders cite speed and efficiency as their primary motivation. That tracks. The concern is that the outputs can look clean and functional while hiding logic errors, performance bottlenecks, or security flaws that only surface later.

A separate paper published June 30 by the Association for Computing Machinery, from US and UK researchers, found that hallucinations from poor prompting are a real risk in vibe coding contexts. They called for significant audit tooling to verify outputs before deployment.

The Enterprise Disconnect

Frank Erickson of 28Stone, a consulting firm serving capital markets, was blunt: the current hype has “done AI a massive disservice.” His argument is that there is a meaningful gap between vibe coding and enterprise software development, and that gap matters at scale. “I get pretty perturbed when our people internally refer to AI tooling as vibe coding,” he said.

Shoard echoed the scaling problem from a different angle. When hundreds of apps get spun up across an org, there is no single patch to push. Each app is its own surface. Not all of them will be scanned.

The Governance Gap

Indonesian researchers, in a paper published last month, proposed a framework that wraps vibe coding inside the standard software development lifecycle: inspect, interpret, and validate AI-generated code at each stage. They also called for continuous technical debt monitoring as part of any governance policy.

The ACM researchers put it plainly: AI works best as an assistant that provides localized code suggestions while leaving overall direction, integration, and validation to the human developer. That framing is the opposite of how most teams are currently using it.

If your organization is encouraging employees to ship vibe-coded apps, the minimum viable governance layer is automated secret scanning on every repo before it goes public.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo