Build1 distinct publisher3 min readUpdated
An August 17 release scans a sandboxed copy of a published app from the outside, then routes confirmed findings to Replit Agent to draft patches. One human click stands between audit and self-certification.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Replit turned on black-box penetration testing on August 17, letting its AI app builder probe a published application from an attacker's perspective and pass confirmed findings to Replit Agent for proposed fixes [1]. The company announced it in a thread on X and a product post by member of technical staff Alexandre Cuoci [2]. The consequence is structural rather than technical: the system that generates the code now also assesses it and writes the remedy.
The mechanics are straightforward. A user launches a Level 3 scan from a project's Security Center, which runs a white-box scan with access to the source alongside a black-box scan that gets only the application's link [4]. Replit says both scans target a full copy of the application inside a private sandbox, keeping the tests away from production users [5]. The external agent clicks through the app while watching its network requests, first testing what an unauthenticated visitor can reach, then signing in as an ordinary user to check whether that account can read another user's records or get into restricted administrative areas [6]. Replit says the scanner also identifies the technologies behind the app and tests failure modes associated with that setup [7].
Replit's own examples make the case for the second perspective better than any framing does. The white-box pass caught a logic flaw that let a user with revoked access keep operating because the application never rechecked an old session [8]. The black-box pass found a separate admin dashboard sitting at a predictable address with no authentication [9], and in a Replit-built multiplayer game it found an endpoint that could be flooded to crash an active match [10]. Replit says the code scanner missed those runtime exposures because the underlying source did not look defective on its own [11]. That is the familiar gap between reading a repository and using a deployed system.
Then the loop closes. Findings feed directly into Replit Agent, which prepares patches for the user to inspect [12], with a human approval step before changes return to the main project and a required republish before fixes reach production [13]. Replit itself notes that an automated patch can change permissions, request handling or application behavior in ways that need product context, even when the vulnerability is real [14]. That approval click is the entire boundary between an audit and a self-certification, and it is being asked of a user who, by the premise of the product, did not write the code under review.
The tiering tells you where this sits commercially. Level 1, which Replit says is free, covers dependency checks and static analysis [15]; Level 2 adds the deeper white-box agent review [16]; Level 3 runs both agents [17]. So the attacker's-eye pass is the top of three tiers, and two of the three see only what the source reveals [25]. Auto-Protect layers on a malicious-package firewall, a web application firewall and SSL/TLS encryption [18].
This has been assembled in stages: a white-box Security Agent that maps architecture, builds a threat model and checks routes and APIs for SQL injection, cross-site scripting and request forgery launched April 21 [19], and Security Center gained multi-project vulnerability review in May [20], putting roughly four months between the first agent and this one [24]. It matches the wider consolidation, with RuntimeWire reporting in June that Agent was expanding into websites, mobile apps, pitch decks and launch videos [21] and a design suite with Figma imports arriving in July [22]. RuntimeWire's framing of the underlying obligation is fair: if someone can publish an app holding customer data in a day, security work has to move at about that speed [26].
Watch whether Replit publishes acceptance and regression rates for Agent-authored patches, whether black-box scanning drops below the top tier, and whether the human approval gate survives contact with volume.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Replit added black-box penetration testing on August 17, giving its AI app builder a way to probe published applications from an attacker's perspective and pass confirmed findings to Replit Agent for proposed fixes.
Replit introduced the feature in a thread on X and an accompanying product post by member of technical staff Alexandre Cuoci.
A user launches a Level 3 scan from a project's Security Center; Replit then runs a white-box scan with access to the source code alongside a black-box scan that receives only the application's link.
Replit says both scans target a full copy of the application inside a private sandbox, keeping the tests away from production users.
The black-box scanner clicks through the application while observing its network requests; it first tests what an unauthenticated visitor can reach, then signs in as an ordinary user to check whether that account can access another user's records or restricted administrative areas.
Replit says the scanner also identifies the technologies behind an application and tests failure modes associated with that setup.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Well-documented release, vendor-sourced capability claims
Existence, timing and mechanics of the feature are concretely documented: a dated release, a named announcing employee, a product post and video, and an itemized tier structure. But every substantive capability and efficacy statement traces to Replit itself, relayed by one publisher that also authored the prior reporting it cites. There is no independent test, no coverage or false-positive data, and the illustrative findings are Replit's own examples.
Shipped and generally available; no feature-level usage evidence
The feature is live and packaged into a stated tier with a free entry level, and it follows two earlier shipped security surfaces (April white-box agent, May multi-project Security Center), which shows sustained product investment. Nothing in the source shows uptake of the black-box scanner itself: no attach rates, scan volumes, customer references or third-party deployments. Platform scale numbers exist but are Replit's own disclosures about the whole product, not this feature.
Mildly overstated: 'penetration testing' framing outruns verified results
The vendor framing borrows the language of penetration testing for an automated agent whose only demonstrated results are self-selected examples, and remediation is described as agent-drafted patches behind one approval click. The publisher partly offsets this by naming the review requirement, the risk that automated patches alter permissions or request handling without product context, the confinement of black-box scanning to the top tier, and existing specialist competitors — which keeps the gap small rather than large.
Strong vendor incentive, explicitly stated in the source
The source states the commercial logic directly: Replit wants inexperienced builders shipping software that handles real users, payments and internal data, and every additional production workload raises the value of hosting and agent credits while raising the stakes of insecure generated code. The same vendor supplies the audit, the fix and the hosting, and is the origin of all capability claims; disclosed scale and revenue targets sharpen the pressure to present security as solved.
Confident on what shipped, weak on how well it works
High confidence that the described feature, tiers and workflow exist as reported, given specific dates, a named spokesperson and cited product material. Low confidence about detection quality, patch safety and real-world use: one publisher, vendor-origin claims, no independent verification, and no adoption or efficacy measurement for the feature.
build
DNS records put Replit inside 62 funded YC startups, and that changes your hosting risk math1 distinct publisher
leadership
Every's 30 people, four products and one cloned editor: the self-driving company in practice1 distinct publisher
invest
Spark's $22M bet that the agent framework layer can stay independent1 distinct publisher
build
Kimi Desktop's second binary: mutable CDN path, no Windows checksum, no signer check1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026