# Vibe coding: uses and limits

Taiga Learning · Worksheet
https://taiga.training/en/lessons/vibe-coding/

Use fictional or approved information. Do not put secrets in this worksheet.

## Learning objectives
- Distinguish exploration from a release decision.
- Identify the missing responsibilities in a convincing demo.
- Choose a safe boundary for a first experiment.

## Exercise
Select a feature from a recent demonstration.
1. Record one result that the demonstration established.
2. Record three questions that remain open.
3. Assign an owner to each question.
4. Name a specific check that can detect each possible failure.
Do not use “make it secure” as a substitute for a specific check.

## Your response
- Scenario and scope:
- Assumptions and open questions:
- Proposed answer or decision, with reasons:

## Verify your response
| Claim or criterion | Evidence or test | Result or gap | Owner |
| --- | --- | --- | --- |
| | | | |
| | | | |
| | | | |

## Next action
- Action, owner, and date:
- When will you review this response?

## Principle to retain
Give people room to prototype with synthetic data. Verify the platform and application before granting confidential data or live API access.

## Sources
- [NIST: Secure Software Development Framework 1.1](https://csrc.nist.gov/pubs/sp/800/218/final)
- [Lovable: Security best practices](https://docs.lovable.dev/tips-tricks/security-best-practices)
- [OWASP: Broken Object Level Authorization](https://api-security.owasp.org/editions/2023/en/0xa1-broken-object-level-authorization/)
- [Stripe: Idempotent requests](https://docs.stripe.com/api/idempotent_requests)

This worksheet supports learning. Completing it does not itself authorize a production change.
