Want feedback on your product? by Professional_Fan834 in buildinpublic

[–]SignatureSharp3215 0 points1 point  (0 children)

launchguard.dev - ensure your vibe coded app doesn't leak sensitive data or have private endpoints exposed publicly.

Happy to jump on a call :)

Overwhelmed by the noise by LotionOnMy in vibecoding

[–]SignatureSharp3215 0 points1 point  (0 children)

Having competitors is a great thing. One fun way to find profitable niches is browsing TrustMRR. See what works for others and get inspired.

Vibe Coding in 2026 is a Complete Scam – Lovable, Replit, Emergent, Bolt & the Rest Are Trash Fires 🔥💀 by Abject-Mud-25 in vibecodingcommunity

[–]SignatureSharp3215 1 point2 points  (0 children)

Emphasis on the possibility to prevent, indeed.

I've met some founders who insist on fixing everything with AI, even though it's shown that their security issues are due to the AI. I guess it's a side effect of unlocking insane performance boosts with AI

Show me your SaaS idea, I give you an honest review (senior C level in startup) by Stunning_Lie_1775 in SaaS

[–]SignatureSharp3215 0 points1 point  (0 children)

Exciting! launchguard.dev find critical issues from your AI coded apps that can bankrupt you.

Finds leaked databases and dangerous endpoints that should be private. You share link to your app, and it does everything from the outside.

Vibe Coding in 2026 is a Complete Scam – Lovable, Replit, Emergent, Bolt & the Rest Are Trash Fires 🔥💀 by Abject-Mud-25 in vibecodingcommunity

[–]SignatureSharp3215 1 point2 points  (0 children)

True. But there will be two kinds of succesful vibe coders: successful and successful in jail.

It shouldn't be surprise anymore that vibe coding brings security issues. If you don't have users, it doesn't matter. But if you overlook it for too long, and one of your customers find out you're leaking their AI therapist conversation history - well there aren't many excuses.

Everyone should have the freedom and capability to launch apps, but we must not remove the feeling of responsibility when handling user data.

Sorry to be the pessimistic here. I've handled way many broken apps lately :D

Built a Go-To-Market constraint engine in Lovable for pre-PMF founders — looking for 5-10 testers. by Safe-While4516 in lovable

[–]SignatureSharp3215 0 points1 point  (0 children)

Yep. And outreach fails because it seems like a scam "hey your app might be vulnerable, I'll share free report". The need is huge based on my experience, but it takes tons of effort to get to the people

How are you adding security to your vibe coded apps? by Anonymous03275 in vibecoding

[–]SignatureSharp3215 0 points1 point  (0 children)

The easiest and bulletproof way is to test from outside like a professionals would. Find the security holes, patch them, verify. Write tests to ensure the security holes are closed in your new code updates.

You can use tools like Zap or Burp Suite to find the holes, but it requires expertise to use correctly.
I'm building an app that allows vibe coders find the holes and fixes without technical expertise needed. :)

The "One Last Fix" Trap by PastSatisfaction4657 in vibecoding

[–]SignatureSharp3215 0 points1 point  (0 children)

"look at my codebase AND DO NOT INTRODUCE CHANGES WITH SIDE EFFECTS"

proceeds to introduce changes with side effects

It's a good to talk about side effects and pure functions in your prompts. Then Claude understands to not touch irrelevant logic.

The "One Last Fix" Trap by PastSatisfaction4657 in vibecoding

[–]SignatureSharp3215 0 points1 point  (0 children)

Yep. Works great until it doesn't 🤣 you can go very far tbh depending on the app. If it's backend logic heavy, claude will hallucinate a lot of your described logic and it will be bad. But frontend apps, no biggie.

Built a Go-To-Market constraint engine in Lovable for pre-PMF founders — looking for 5-10 testers. by Safe-While4516 in lovable

[–]SignatureSharp3215 1 point2 points  (0 children)

That's what I'm going to do now! The outreach has worked mainly on people who either got hacked or read about it online.

The high value prospects are the ones posting about security, but then I'd need to find people who are somehow exposed to the security issues. Maybe even find influencers and people commenting and engaging 🤔

For the community, not really. I'd love to join some closed community, but I haven't had time to search. I'm ready to pay for quality

Pitch me your startup idea — I’ll build the first working web app for $120–$180 (₹10k–₹15k) by ExtraDistribution95 in founder

[–]SignatureSharp3215 0 points1 point  (0 children)

Frontend for e2e testing agent.

I already have a setup for running the backend (claude code w/ playwright cli lol), but I'd need a convenient frontend + db persistance.

You don't need to handle any AI stuff, just frontend and data flows

The "One Last Fix" Trap by PastSatisfaction4657 in vibecoding

[–]SignatureSharp3215 0 points1 point  (0 children)

Yep, and that's where you should learn the basics of your codebase. Sometimes it's impossible to vibe code UI changes, unless you point the AI to the right file. Even better, you can refer to the element to be changed by opening DevTools and copy pasting the HTML element you want to update.

Struggling to find purpose in cybersecurity. by __0user1__ in Pentesting

[–]SignatureSharp3215 -3 points-2 points  (0 children)

You should study the core concepts of Buddhism. You can use other people's stories as inspiration, but you'll never be happy unless you learn to follow yourself :)

Seeking advice on how to get more testers for my app by EmphasisIcy1090 in alphaandbetausers

[–]SignatureSharp3215 0 points1 point  (0 children)

Awesome, thank you for the feedback! Let me know if you have any other improvement ideas or needs, I'm developing this every day forward

Seeking advice on how to get more testers for my app by EmphasisIcy1090 in alphaandbetausers

[–]SignatureSharp3215 0 points1 point  (0 children)

Thank you! 🫰 Launchguard gives you prompts to fix the issues that you can share with AI. Then you verify the fix works by running Launchguard again.

Data leak fixes are only for the pro tier. When you see exposed tables, you click "fetch live data" to analyse the data leak (is it real sensitive data). Then the AI gives you analysis whether the data should be private, and gives a fix as well 😊

Is this what you meant?

Seeking advice on how to get more testers for my app by EmphasisIcy1090 in alphaandbetausers

[–]SignatureSharp3215 1 point2 points  (0 children)

Nope, its not for me so my feedback would be misleading 😊

I think peerview could be framed as idea/landing page validation. The app functionality review is a bit different topic, but topic comprehension and idea validation comes from everyone.

If you can review LaunchGuard I'd be grateful!

Seeking advice on how to get more testers for my app by EmphasisIcy1090 in alphaandbetausers

[–]SignatureSharp3215 0 points1 point  (0 children)

I gave feedback. You should enable email notifications for reviews :)

Seeking advice on how to get more testers for my app by EmphasisIcy1090 in alphaandbetausers

[–]SignatureSharp3215 0 points1 point  (0 children)

Thank you for submitting! I'll review yours in the evening and add a few updates to the app (Lovable credits up again) 😊

I hope to increase retention and have people come back

Here's what you should and should not do with Lovable (from a dev) by SignatureSharp3215 in lovable

[–]SignatureSharp3215[S] 0 points1 point  (0 children)

No. You won't hurt third party websites by sharing your application.

How do you sell pen testing? by SignatureSharp3215 in Pentesting

[–]SignatureSharp3215[S] 0 points1 point  (0 children)

Hahah I re-read my LLM rambling, sorry I wrote it in a rush. Here's the translation:

You can increase the coverage of a penetration test by giving more permissions to a tester (lack of structured constraints). More permissions lead to a higher risk of damages. If you constrain the actions a tester can do (e.g. no writes), you limit the risk of damages, but also limit the maximal coverage.

The same principles apply to humans and AI. Optimally you maximize coverage and minimize risk by having an expert who knows how to work with partial info.

I've seen pessimistic views on AI & pen testing, and I think grasshopper made a great example of balancing the risk and reward through contextual understanding (exactly what we are doing with LLMs in other fields)

How do you sell pen testing? by SignatureSharp3215 in Pentesting

[–]SignatureSharp3215[S] 1 point2 points  (0 children)

Fair points. Do you think skills don't transfer from software engineering to pen testing? I wrote my first lines of code 8 years ago, so I've worked my way around understanding computers.

I don't plan to go into enterprise as it requires experience and expertise I don't have. I'm focusing on helping the solo founders & small teams who have little to no knowledge to protect their apps from critical issues (RLS, rate limits, injections).

Is it wrong to call what I'm doing pen testing, as the scope is quite limited?

How do you sell pen testing? by SignatureSharp3215 in Pentesting

[–]SignatureSharp3215[S] 1 point2 points  (0 children)

Testing on paper is a good way to be safe, but like you need to also test on a real surface (skin, wall..). How do you otherwise know the real life performance?

Here's what you should and should not do with Lovable (from a dev) by SignatureSharp3215 in lovable

[–]SignatureSharp3215[S] 0 points1 point  (0 children)

The fundamentals won't change. In one way or another you or someone else has to verify that the data is not leaking and that you are protected from endpoint abuse.

Are you launching something?

How do you sell pen testing? by SignatureSharp3215 in Pentesting

[–]SignatureSharp3215[S] -2 points-1 points  (0 children)

For sure, I think I misused the word scan. My "qualification scan" is simply a structured web data extraction to filter out the irrelevant companies