40%+ of AI-Generated Code Has Security Issues; We Open-Sourced a Way to Help
Research indicates that over 40% of AI-generated code contains security issues, often due to missing framework- and version-specific security details. To address this, an open-source project called AI Code Security Cards provides library-specific security guidance for developers and AI coding agents. The project covers more than 60 libraries and frameworks across multiple programming languages, offering practical instructions to mitigate common security pitfalls. This initiative aims to improve the security posture of AI-generated code by guiding coding agents on unsafe defaults, validation, authentication patterns, and security changes between library versions.
AI Analysis
Technical Summary
Studies have found that a substantial portion (over 40%) of code generated by AI coding agents contains security vulnerabilities, primarily because these agents often overlook framework- and version-specific security considerations. To mitigate this, the AI Code Security Cards project offers an open-source collection of library-specific security instructions designed to guide AI coding agents and developers. The cards cover a wide range of libraries and frameworks (60+), including popular ones like Django, FastAPI, Rails, Spring Framework, Laravel, Express, React, and various Go and Rust frameworks. The guidance addresses issues such as unsafe defaults, input validation, authentication patterns, and changes in security behavior across library versions. The project is a continuation of PhD research on large language model-generated code security and is available for integration via an AI skill or direct use from the GitHub repository and website.
Potential Impact
The impact is that AI-generated code, if used without additional security guidance, may introduce vulnerabilities due to overlooked security best practices specific to frameworks and library versions. This can lead to insecure applications if the generated code is deployed without review or mitigation. The availability of AI Code Security Cards helps reduce this risk by providing targeted security guidance, potentially lowering the incidence of vulnerabilities in AI-generated code.
Mitigation Recommendations
No official patch or fix is applicable as this is not a software vulnerability but a security risk associated with AI-generated code quality. The recommended mitigation is to use the AI Code Security Cards project, which provides practical, library-specific security guidance for AI coding agents and developers. Integrating these cards into AI coding workflows can help address common security issues in generated code. Users should follow the installation and integration instructions available on the project's GitHub repository and website. Regularly updating the cards and contributing feedback to the project can further improve coverage and effectiveness.
40%+ of AI-Generated Code Has Security Issues; We Open-Sourced a Way to Help
Description
Research indicates that over 40% of AI-generated code contains security issues, often due to missing framework- and version-specific security details. To address this, an open-source project called AI Code Security Cards provides library-specific security guidance for developers and AI coding agents. The project covers more than 60 libraries and frameworks across multiple programming languages, offering practical instructions to mitigate common security pitfalls. This initiative aims to improve the security posture of AI-generated code by guiding coding agents on unsafe defaults, validation, authentication patterns, and security changes between library versions.
Reddit Discussion
Hi everyone,
AI coding agents can develop code that works, but they often miss framework- and version-specific security details.
So we built AI Code Security Cards: open-source set of library-specific practical security instructions for coding agents.
The cards guides AI agents to cover points like unsafe defaults, validation, auth patterns, and security changes between library versions. We currently have cards for 60+ libraries and frameworks across various languages, including Django, FastAPI, Rails, Spring Framework, Laravel, Express, React, and several Go and Rust frameworks.
This project is a continuation of my PhD research on LLM-generated code. Our work and other studies have found security issues in a substantial share of generated code, including more than 40% in various evaluations.
The easiest way to use the cards is by installing the AI skill. You can find installation instructions in the GitHub repository or on the website’s integration page. You can also browse the cards on the website or add individual cards directly to your agent’s rules.
Website: https://securitycards.rewarelabs.com/
GitHub: https://github.com/Reware-Labs/securitycards
Would love feedback on:
- Which libraries we should cover next?
- Where this would fit in your workflow?
- What security failures have you seen in AI-generated code?
- What would make the cards more useful or trustworthy?
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Studies have found that a substantial portion (over 40%) of code generated by AI coding agents contains security vulnerabilities, primarily because these agents often overlook framework- and version-specific security considerations. To mitigate this, the AI Code Security Cards project offers an open-source collection of library-specific security instructions designed to guide AI coding agents and developers. The cards cover a wide range of libraries and frameworks (60+), including popular ones like Django, FastAPI, Rails, Spring Framework, Laravel, Express, React, and various Go and Rust frameworks. The guidance addresses issues such as unsafe defaults, input validation, authentication patterns, and changes in security behavior across library versions. The project is a continuation of PhD research on large language model-generated code security and is available for integration via an AI skill or direct use from the GitHub repository and website.
Potential Impact
The impact is that AI-generated code, if used without additional security guidance, may introduce vulnerabilities due to overlooked security best practices specific to frameworks and library versions. This can lead to insecure applications if the generated code is deployed without review or mitigation. The availability of AI Code Security Cards helps reduce this risk by providing targeted security guidance, potentially lowering the incidence of vulnerabilities in AI-generated code.
Defensive Guidance
No official patch or fix is applicable as this is not a software vulnerability but a security risk associated with AI-generated code quality. The recommended mitigation is to use the AI Code Security Cards project, which provides practical, library-specific security guidance for AI coding agents and developers. Integrating these cards into AI coding workflows can help address common security issues in generated code. Users should follow the installation and integration instructions available on the project's GitHub repository and website. Regularly updating the cards and contributing feedback to the project can further improve coverage and effectiveness.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":30,"reasons":["external_link","newsworthy_keywords:rce","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["rce"],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a7308b2bf8831d539b04c2e
Added to database: 08/05/2026, 09:56:02 UTC
Last enriched: 08/05/2026, 09:56:12 UTC
Last updated: 08/05/2026, 12:11:02 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.