Is My Claude Code App Secure? What Agents Quietly Skip
By Pouyan · Updated August 2026
I use Claude Code every day. I am not going to tell you to stop, and I would be a hypocrite if I did.
I want to talk about one thing only. You told the AI what you wanted, it worked for about forty minutes, it changed thirty-one files, and you read maybe four of them. Nobody reads thirty-one files at eleven at night when it all works. I do not either.
Here is the uncomfortable bit. Almost everything that goes wrong in apps built this way is sitting in plain sight in those files you did not read, and is completely invisible when you use the app. It works. It has always worked. Clicking around your own product tells you nothing at all.
What this actually looks like
Let me be specific, because I think people imagine hackers and clever tricks, and it is nothing like that.
Your app keeps its information in a database. Your website needs to reach that database, so it carries a key, and that key is inside the page your website sends to every single visitor. That part is normal and fine.
What is supposed to stop that key handing over everything is a rule saying who is allowed to read what. On a table your AI created, that rule is off unless somebody switched it on.
If it is off, then right now, from a phone, on the bus, a stranger can put one address into a browser and read your entire customer list. Names. Email addresses. Whatever else you collected. No password, no hacking, no skill. They ask, and your database answers, politely, the way it was built to.
I am not saying this is definitely happening to you. I am saying it is the single most common thing I find, it takes about a minute to exploit, and you would have no way of knowing.
Three things you can check yourself
All from your own browser. No code. About ten minutes for all three, and they cover most of what actually goes wrong.
Can strangers read your customer list?
Open your database dashboard. If you used Supabase, that is the Table Editor. Look down the list of tables for the word Unrestricted.
That word means there is no rule. Anyone can read it. If you see it next to a table holding anything about a person, stop reading this page and go and deal with it. The step by step is here.
Does your login actually keep people out?
There is a difference between hiding a door and locking it. AI is very good at hiding doors. If your app decides what to show by hiding buttons, then everything behind those buttons is still sitting there for anyone who knows the address.
Open a private browsing window. Do not sign in. Type in your dashboard or admin address directly. If it sends you to a login screen, good. If your information loads, the lock was painted on.
Can one customer read another customer's things?
Sign in as yourself and look at your web address while you are viewing something of yours. If there is a number in it, change it. Try a few.
You should see nothing, or an error. If you can see somebody else's details, then every one of your customers can read every other customer's details, and has been able to since the day you launched. This is the one I find most often after the database, and it is usually a small fix once somebody knows to look.
The one that caught me
There is a fourth thing, and it is the one I got wrong myself, so I will tell it properly.
When your app connects to something else, like Google or GitHub, it has to ask that service for permission. There is a wide version of that request and a narrow one. The wide one always works first time. The narrow one sometimes takes another go.
You can guess which one an AI picks when it is trying to make your feature work.
On a tool I built, mine was asking every person who signed up for full access to everything they had ever written. All of it. I never asked for that and I did not know it was happening. A developer signed up, saw the request, refused, and told me. He was being kind. Most people would have closed the tab, and I would have sat there wondering why nobody was signing up.
If your app connects to anything, go and read what it asks people for. Imagine a stranger's app asking you for that. Your users are being asked exactly that, and most of them are not reading it.
What I honestly cannot tell you from here
Those checks are worth doing and they catch most of it. But I would rather be straight with you about what a web page cannot do.
It cannot see the half of your app that sits behind the login, which is usually where the information worth stealing lives. And it cannot tell you whether a rule that exists is the rule you meant, which is a different question and a harder one.
For that, somebody has to actually sit down with it.
If you would rather not do this on your own
Send me the address of your app. I will go through it myself before we speak, then we take half an hour and I will tell you what I found in normal words, no jargon, no lecture.
It is free and there is nothing to buy at the end of it. And if your app turns out to be in good shape, I will tell you that and you will have lost half an hour, which is a perfectly good afternoon's work. It is more than I managed on my own.
You will not get told off for using AI to build it. I used it this morning.
Common questions
Is an app built with Claude Code safe?
It is as safe as what you asked for. The AI builds the thing you describe. It does not stop and say that you forgot to decide who is allowed to see your customers' details, and the app works perfectly either way, so you never find out by using it.
What goes wrong most often?
Somebody who is not you being able to read your customer list. That is the big one. After that: a login screen that looks like it protects things but does not, and your app asking your users for far more access to their accounts than it needs.
How do I check without being technical?
Three things you can do in about ten minutes, all from your own browser. Open your database dashboard and look for the word Unrestricted. Open your own site in a private window while signed out and try to reach your admin page. And change a number in your web address to somebody else's and see whether their information appears.
My app works fine. Doesn't that mean it's OK?
Unfortunately not, and this is the hard part to accept. An app where anyone can read everything and an app that is properly locked look exactly the same when you are the one using it. The difference only shows up when a stranger goes looking, and by then they have already looked.
Not sure if yours is affected?
Send me your app's address. I'll look at it myself before we speak, then we take half an hour and I'll tell you what I found in normal words. Free, no pitch, and if it's in good shape I'll tell you that too.
Pouyan Ahmadpour · engineer · Amsterdam
Keep reading
- Is My AI-Built App Ready for Real Users? What Breaks First
The parts that only fail on the day you succeed.
- Is My Lovable App Secure? A Plain-English Safety Check
The checks that matter before you let real users in.
- Supabase Row-Level Security
The single most common way vibe-coded apps leak user data.
- The Vibe-Coding Security Checklist
12 checks between a working prototype and a safe product.
- My Vibe-Coded App Got Hacked
The calm, step-by-step response when the worst has happened.
- My Supabase API Key Is Exposed
Found your key in the code? Here's what's actually at risk.
- Is My Bolt App Secure? The Checks That Matter Before Launch
What to check on a Bolt.new app before real users arrive.
- Is My Replit App Secure? A Plain-English Safety Check
The Replit-specific gotchas, plus the universal checks.
- Firebase Security Rules
The Firebase version of the open-database problem.
- What Does It Cost to Secure a Vibe-Coded App?
What an audit and fixes actually cost, and what you get.