> Running code is dangerous.
Code can make your computer do stuff. If you run code in an environment where it has the possibility to do harm, then it is a possibility, and therefore a risk. Whether or not you accept that risk depends on the situation, but it is important to realise that the risk exists.
> I don't really see how its provenance matters
The fact that the code was vibe coded does not change the capabilities it has. If you run random code written by a human with root access, the code can do what root can do. If you run random vibe-coded code with root access, the code can do what root can do.
When you run code, what the code is allowed to do in the environment it is running is independent from who or what wrote that code.
> you should not run code you don't trust, period.
Trust does not mean that you have to review all the source code everyday, yourself. Trust means that you accept the risk given the provenance.
When you drive you car, you trust that it won't explode. You don't review the whole car assembly every day. When you cross a bridge, you trust that it won't collapse. You don't check the whole structure everytime yourself.
When you run your laptop, you trust that the battery won't catch fire. You trust that your OS isn't a malware.
In your life, you trust many many things. Many times you don't have a choice, many times it's institutional trust ("I live in a country where bridges don't collapse", for instance).
Now when you run code you find on the internet, I'm sure you apply that. Say it comes from Google: you probably trust it (after all, if you don't trust Google you're pretty much screwed).
Now if a random username on Reddit tells you to execute some code, do you happily do it? I don't think so. At least you shouldn't unless you understand what it does.
What's the difference between random code you find on Reddit and vibe-coded code? I don't see one. I don't base my trust on the fact that it was written with AI.
The fact that it comes from AI means "it is not an author that I trust, but it doesn't mean that the code is malware". I just need to find another way to trust it (maybe someone else audits it, maybe I do, maybe I run it in an environment where it doesn't matter, etc).