DEV NEXT AI
21 subscribers
1.01K photos
241 videos
148 files
6.1K links
All about NextJS, Python, Javascript, Node, Frontend, Backend
Download Telegram
Vibe coders are getting sued.

People are shipping apps with real users and skipping the boring stuff that kills them.

A 20+ year dev shared the pre-launch checklist every AI builder needs.

I added what I learned after shipping 60+ apps at the agency.

Don't skip this:

1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives.

2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix.

3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs.

4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture."

5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught.

6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time.

7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes."

8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it.

9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day.

10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods.

11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages.

Build fast. Just don't ship naked.

(full breakdown in my article below)
Andrej Karpathy just dropped 12-page PDF on "Graph Engineering" for multi-agentic systems

the shift: Karpathy's loop runs 700 experiments and forgets all of them. A graph remembers forever

here's the full system:

step 1 → build one loop: generate, critique, revise. 630 lines, 700 experiments in 48 hours

step 2 → go parallel: agents in separate worktrees, same repo, different branches, no conflicts

step 3 → add a knowledge graph: extract entities, resolve aliases, assemble typed edges, query through subgraphs

step 4 → ground your evaluator: it checks claims against graph edges, not vibes

step 5 → plug the graph as shared memory. workers write to it. evaluators fact-check against it. Loops persist overnight

step 6 → the agent forgets. the graph does not. stop rebuilding context from scratch every session

Karpathy ran 1 agent in 1 direction. Anthropic's graph runs 1,000 with shared memory - same model, it's the architecture

this 11-page PDF changed how I'm building multi-agent systems today

read it now - then explore the full graph engineering article below ↓
Great idea 🔥

Here’s a more complete and robust prompt for Claude (works especially well with Projects or when you upload the codebase):

Analyze my entire codebase in depth.

Generate TWO complete, ready-to-use deliverables:

1. A single self-contained HTML file (Tailwind CDN + dark theme) that includes:
- Interactive architecture diagram (nodes + edges)
- Flows panel on the right
- When selecting a flow, highlight the full path in the diagram and show detailed steps below
- Tooltips with descriptions for each component
- Clean, professional, and responsive design

2. A structured JSON with this exact shape:
{
"nodes": [...],
"edges": [...],
"flows": [
{
"id": "...",
"name": "...",
"description": "...",
"steps": [...]
}
]
}

The HTML is for humans. The JSON is for the next AI agent so it can fully understand the architecture and work on new features without losing context.

Deliver both files complete, with nothing omitted.
Analyze my codebase. Generate a self-contained HTML (Tailwind CDN, dark theme) with an interactive architecture diagram + interactive Flows section (select and highlight path + steps).

And a JSON {nodes, edges, flows: [{steps}]} for AI agents.

Deliver both complete.
How to become an AI-native company:

1. Establish a unified Model Context Protocol (MCP) or API gateway to enable team connectivity with internal systems.

2. Develop a centralized corporate knowledge repository:
- Integrate static context data, including organizational identity, operational guidelines & product documentation.
- Integrate dynamic context data, including meeting minutes, email correspondence, Slack communications, and active project details.

3. Implement a corporate orchestration framework to instruct AI on interacting with the knowledge repository and internal systems.

4. Integrate the workforce into the orchestration framework to establish a self-improving feedback loop that learns from employee activities.

5. Develop a model-routing layer to evaluate and distribute tasks to the appropriate model at the optimal time, thereby mitigating vendor risk.

6. Construct autonomous agents atop the corporate orchestration framework.
Channel photo updated