No thanks.
No thanks.
In your 4+ years of “experience,” have you acquired the experience necessary to protect anybody’s GitHub, slack, or any other enterprise systems from the numerous security concerns that you’re just hand-waiving away?
Not all “devs” use AI, and very few companies would trust a fully vibe-coded enterprise system plugin with no security team, no enterprise support, no GDPR documentation, and all fielded by a team with fewer than five years of experience.
That seems like the path to breaches, or to having an agent take destroy sensitive systems, or both.
I am concerned that you haven’t adequately explored and mitigated security and reliability risks involved here before asking folks to YOLO your app into their critical infrastructure.
It seems more likely that such a team would have poor security controls, insufficient staff training, and may themselves be threat actors.
For an enterprise tool like this, one which integrates with two or more other sensitive systems, I would expect a vendor to have some manner of independently audited security certification such as ISO-27001.
FWIW I don't disagree with you. I also assume people are vibe-coding things. I just don't think it's fair to assume that means the devs are taking that code and firing it straight up to a production server. They're probably fixing the problems and making it better. I know I do that in my code (most of the time.)
Sites with generic stock photos were always a bad sign when dealing with websites in the past as well.