做产品 PMaker
空格的键盘
AI 写代码又快又勤 —— 安全检查也得跟上,三分钟 ① 扫密钥 全仓库搜密钥、密码、Token 已提交的,删掉不够,吊销重发 ② 查权限 每个接口:有没有校验登录、有没有校验范围 用 A 的会话访问 B 的资源,看拦不拦得住 ③ 查拼接 输入进查询 / 命令 / HTML 的地方 必须参数化,不能拼字符串 还有一招 让 AI 自己先自查:提示词里加一句「密钥不硬编码、每个接口校验权限、输入全部参数化」 AI 代码和人写代码一样,过评审、过扫描、过测试 —— AI 是流水线,你是质检

AI 不会故意留漏洞,但它会忠实复刻它学到的「常见写法」——而常见写法里恰好全是这三类坑。检查的责任在你,不在工具。

Security Check for AI Code

AI writes code fast and often, but it won't automatically write secure code for you. Its output keeps falling into three kinds of traps: hardcoded secrets, broken access control, injection. Run them before launch — three minutes can avoid one incident.

What you'll run into
  • API 密钥明晃晃写在代码里,跟着仓库一起上了云
  • 接口只查了「登录了没」,没查「能不能看这条数据」
  • 用户输入直接拼进了数据库查询字符串

Three high-frequency traps

Know what the traps look like first, then you know what to check:

The three-minute checklist

Whether the code was written by AI or a human, run this checklist before launch:

三条里最值得亲手试一次的,是越权 用户 A 的会话 GET /orders/B-1024 403 拦住了 200 返回了 这才叫查了权限 只查了「登录没」 ① 扫密钥 全仓库搜密钥、密码、Token。发现已提交的,立刻吊销重发——只是删掉远远不够。 ② 查权限 逐接口问两遍:查登录了吗?查「当前用户对这条数据的访问权」了吗? ③ 查所有「拼」的地方 用户输入进入查询、命令、HTML 时,必须参数化,不能字符串拼接。
这三条三分钟就能过完,但它们挡住的是AI 生成代码里最高频的三类坑。还有一条成本为零的:在提示词里直接要求「密钥不硬编码、每个接口校验权限、用户输入全部参数化」——效果立竿见影。

Why AI is especially prone

Three reasons, all tied to how AI works:

The finer mechanics live in Common Flaws in AI Code. One more belief to add here: don't ask "why does AI keep writing insecure code" — ask yourself why you're not reviewing. Faster tools don't mean higher quality; the security line was always a human's to hold. Before handing something to AI, first judge whether this job deserves it — see What to Hand to AI.