AI Security Podcast

Vibe Coding, Slopsquatting, and the Future of AI in Software Development

9 snips
Jun 12, 2025
In this engaging discussion, Guy Podjarny, founder of Snyk and Tessl, dives into the future of AI in software development. He introduces 'vibe coding,' where developers increasingly rely on AI-generated code with less oversight, sparking opportunities and significant risks. The conversation also touches on 'slopsquatting,' a new security threat from AI-generated fake library names. Guy emphasizes the shifting role of developers towards managing AI workflows and highlights the importance of clear specifications and rigorous testing in a rapidly evolving tech landscape.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Three Chapters of AI Coding

  • AI-assisted coding evolved in three chapters: code completion, vibe coding, and agentic development.
  • Vibe coding delegates more control to AI, enabling creation without deep code review but with higher risks.
INSIGHT

Understanding Vibe Coding

  • Vibe coding means accepting AI-generated code without reviewing it, especially for temporary or disposable apps.
  • This openness benefits non-coders but introduces significant maintenance and security risks.
ADVICE

Defend Against Slopsquatting

  • Use whitelisting for allowed libraries to avoid slopsquatting risks.
  • Employ external rule sets and automated security tools to catch fake or malicious AI-generated dependencies.
Get the Snipd Podcast app to discover more snips from this episode
Get the app