Learning paths / Vibe coding to production / Security of AI-written code

Check: security of AI-written code

Knowledge check · 5 min · Module 6, lesson 4 of 45 min left in this module

Module 6 · Security of AI-written codeLesson 4 of 4

Goal: Confirm you can keep secrets out of code, spot a missing authorization check, and vet a dependency an agent suggests.

Four questions: three on this module, one on Module 4. Every answer explains itself, right or wrong.

An agent moves a key into process.env.API_KEY and compares it with a request header. The variable isn't set on the server. What can happen?
PATCH /api/notes/:id updates a note by ID. The code checks the user is signed in, then saves. What's missing?
Your ComputeSphere app needs a payment provider key. Where does the value live?
From Module 4: reviewing an agent's diff, you see a new package in package.json that the brief didn't ask for. What is it?

Retry as often as you like.