Matt Palmer's scan found 170 of 1,645 Lovable showcase apps leaking data through inadequate Row Level Security, the same kind of gap Wiz found at Moltbook. Before launch, an AI-built app needs a review that tests the database rules behind its public key.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap0
- Incentives35
- Confidence55
A reviewer with eight years' experience reached a restaurant app's admin functions from his non-admin session because its endpoints never checked his role. The app was built with RBAC middleware, but the role check ran only in the browser.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence40
The gate is a pure function that imports nothing and runs under plain node. The proof it works is a six-case suite scoring 1 of 6 against the ungated resolver and 6 of 6 once the gate is wired in.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives25
- Confidence50
Exploitation is now the top initial-access vector at 31% of breaches. The median defender needs 43 days to close a known-exploited flaw. Both figures reach operators through a guide selling the fix.
Reality
- Evidence45
- Adoption22
- Hype gap+40
- Incentives88
- Confidence58
Given a mundane goal, an open-source assistant cancelled a stranger's reservation on a live booking system that had no authorization checks on cancellations. Nobody instructed it to attack anything.
Reality
- Evidence34
- Adoption16
- Hype gap+38
- Incentives52
- Confidence41
A dev.to walkthrough shows four low-to-informational findings composing into one serious attack path. The chain is the deliverable; the ranked inventory is only a parts list.
Reality
- Evidence20
- Adoption
- Insufficient
- Hype gap+18
- Incentives32
- Confidence38