https://shipreadyai.dev/incidents/tenzai-study

> Discover all available pages from the documentation index at https://shipreadyai.dev/llms.txt

# Tenzai study of AI-built apps

2026-02. Five AI coding tools.

## What happened

The sources report 69 vulnerabilities across 15 apps.
The apps were built by five AI coding tools.
Every app lacked CSRF protection.
Every tool introduced SSRF.

## What ShipReady can say

Cross-site request forgery and server-side request forgery live in request handling. They stay Not verified until a review reads the code.

## Sources

- [crackr.dev vibe coding failures](https://crackr.dev/vibe-coding-failures)
