"Vibe编程"作为一种新兴开发方式,通过AI聊天机器人快速生成代码,使没有编程基础的用户也能够迅速创建应用程序[1]。这一技术正获得广泛采纳,全球约84%的开发者在2025年正在使用或计划使用AI编码工具[1],其中约63%的Vibe编程平台用户缺乏编程背景[1]。
然而,安全问题成为这一便捷方法的重大隐患。研究发现,公开发布的AI生成应用中存在数千个安全漏洞和泄露的秘密,其中约45%的AI生成代码样本在标准安全测试中不合格[1]。这些问题主要源于"自动化偏差"现象,即用户倾向于盲目接受自动化系统的建议而缺乏充分审查[1]。因此,虽然Vibe编程适用于实验原型和个人工具开发,但涉及个人信息或财务交易的应用仍然需要人工审查和严格测试[1]。
"Vibe coding"—the practice of using AI chatbots to rapidly generate application code—has democratized software development by enabling users without programming backgrounds to build functional applications quickly[1]. An estimated 84% of global developers are using or planning to use AI coding tools in 2025[1], with approximately 63% of vibe coding platform users having no programming experience[1]. The approach has made experimentation and prototype development accessible to a much broader audience.
However, research has uncovered significant security vulnerabilities embedded in this convenience. Thousands of security flaws and exposed secrets have been discovered in publicly released AI-generated applications[1], and approximately 45% of AI-generated code samples fail standard security testing[1]. The risks are compounded by a phenomenon known as "automation bias"—the tendency for users to accept recommendations from automated systems without sufficient scrutiny[1]. While vibe coding remains suitable for experimental projects and personal tools, applications that handle personal information or financial transactions require rigorous human review and testing before deployment[1].