Preliminary research
The API Made Me Do It: Do Bad APIs Lead AI to Generate Vulnerable Code?
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
A worked experiment on constraining generated web application code through safer APIs and build gates. The slides show failed restrictions, generated workarounds and revised gate designs, with control and constrained applications for inspection. Limited runs and AI review ratings do not establish a general improvement in security.
Record
- Researcher
- Yariv Tal
- Published by
- Secure From Scratch
- Topic
- AI
In the archive
Related sources
- BusyBee Generation Test — OWASP Untrust Constrained Application Repository
- BusyBee Generation Test — Plain Control Application Repository
Tags
This page is the archive's own catalogue record. The research is the work of Yariv Tal, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .