Amjad Masad on Replit's New Black-Box Pen Testing: 'It's Not Enough to Scan Your Code for Vulnerabilities'
X/Twittervia @amasad·medium signal
Replit shipped black-box penetration testing for Replit apps on Aug 17 — security scans that probe deployed apps the way external attackers would, rather than reading source. Masad's framing (309 likes) is that static vulnerability scanning is insufficient and 'it's important to try to break them with pen testing.' This is a notable admission of the vibe-coding security gap from the CEO of the platform most associated with non-engineers shipping production apps.