My understanding is the notion is about getting an application to "work" without any underlying theory of operation or evaluation of the imported context.
That said, all of the full fat frameworks make it pretty easy to define what should and shouldn't be visible to what users, the use case that he has would not have been harder to do using rails, phoenix, django, etc as a backend, and it would have been very easy to control the failures that he had.
It has it's dangerous spots, and it's uncomfortable spots, but we pretty much know all about them already, and usage is heavily documented.
Or you can try ORM74 and hope it is faster and more secure than THE standard way. Gamble away.
Or maybe try Framework 74b which abstracts away the ORM
Pray tell, what is a good choice then?
.
.
... anything you already know yourself to secure so you can correct the "AI"
I think that this is the answer. Maybe someone who is great with Postgres Row Level Security will have an OK time with Supabase security, even if they are vibe coding. They wouldn't think of asking the AI for something that won't work.