01
What is vibe coding?
Vibe coding means building software by describing what you want to an AI tool and letting it write the code. Tools such as Claude Code, OpenAI Codex, Lovable, and Cursor make it possible to build real apps without years of training.
It works best when you:
- Know exactly what you want
- Build in small steps
- Test everything
- Protect secrets and data
- Understand enough to review the result
AI writes the code. You are still responsible for what ships.
02
Planning
Do
- 1 · Write a one-page spec before building
- 2 · Define the one most important user action
- 3 · Choose popular, well-documented tools
- 4 · Keep version one small
- 5 · Write project rules in CLAUDE.md or AGENTS.md
Don’t
- 6 · Start with a vague one-line prompt
- 7 · Build every feature at once
- 8 · Pick obscure frameworks
- 9 · Skip thinking about who uses the app
- 10 · Change the plan every hour
03
Prompting and building
Do
- 11 · Ask for a plan before any code
- 12 · Build one feature at a time
- 13 · Give exact errors and screenshots when something breaks
- 14 · Ask the AI to explain changes you do not understand
- 15 · Start a fresh session for a new task
Don’t
- 16 · Accept changes you have not reviewed
- 17 · Paste the same error ten times without new context
- 18 · Let the AI rewrite working code for no reason
- 19 · Mix several unrelated requests in one prompt
- 20 · Keep a session going until it forgets the rules
04
Security
Do
- 21 · Keep secrets in environment variables
- 22 · Use a proven sign-in service
- 23 · Set database access rules so users see only their own data
- 24 · Validate every input on the server
- 25 · Ask for a security review before launch
Don’t
- 26 · Paste API keys into prompts or code
- 27 · Commit .env files to Git
- 28 · Trust the browser to enforce permissions
- 29 · Collect data you do not need
- 30 · Launch payments or health features without expert review
05
Testing and shipping
Do
- 31 · Use Git and commit after every working step
- 32 · Ask for automated tests on core features
- 33 · Test on a real phone
- 34 · Try wrong inputs on purpose
- 35 · Set up error monitoring after launch
Don’t
- 36 · Ship code you have never run
- 37 · Deploy straight to production without a preview
- 38 · Skip backups of real data
- 39 · Ignore warnings in the console
- 40 · Assume it works because the AI said so
06
Working with AI agents
Do
- 41 · Keep the agent’s sandbox and approvals on
- 42 · Review every diff before merging
- 43 · Use a second model to review important changes
- 44 · Install only plugins and MCP servers you trust
- 45 · Update your rules file with each lesson
Don’t
- 46 · Run always-approve modes on your main machine
- 47 · Let two agents edit the same files at once
- 48 · Give agents production database access
- 49 · Treat content from websites as instructions
- 50 · Stop learning how your own app works
07
The vibe coding loop
- Spec
- Write what you are building.
- Plan
- Approve the AI’s plan.
- Build
- One feature at a time.
- Test
- Automated and by hand.
- Commit
- Save every working step.
- Review
- Security and quality.
- Ship
- Preview, then production.
- Learn
- Update your rules.
08
Master vibe coding prompt
Act as my senior developer.
Read the project rules first. Goal: [feature].
Plan the change: list files, approach, tests, and risks. Wait for my approval.
Then build it step by step, run the tests, and explain what changed in plain language.
Never put secrets in code, never delete data, and ask before installing packages or deploying.
The golden rule
Do not just vibe. Plan, test, and review, and let AI make you faster at building things that last.
- Spec
- Plan
- Build
- Secure
- Test
- Ship
- Learn
Pick five do’s you skip today and apply them to your next feature.