AI-Generated Code Security — AI-Aware SAST & Provenance | Vulnerabilities.ai™
Marketplace/Category 06 · Securing the AI you deploy

AI-Generated Code

Code produced or substantially shaped by AI tools — vibe-coded apps included — carries risks generic static analysis doesn't catch: hallucinated dependencies, insecure patterns absorbed from training data, and ambiguous licensing provenance.

This is a genuinely new marketplace category: AI-aware SAST, dependency-hallucination detection, and code-provenance tracking for a development workflow where a growing share of commits never had a human write the first draft.

Looking for help in this category?
Get matched with a vetted partner.

Tell us what you're trying to solve and we'll connect you with a vetted partner.

Get Matched with a Partner →
What AI-Generated Code covers

The subcategories, in practitioner terms.

AI-aware static analysis
SAST tuned to catch patterns and hallucinated APIs specific to AI code generation, not just traditional vulnerability classes.
Dependency & provenance tracking
Detection of hallucinated or non-existent packages — "slopsquatting" targets — before they ship.
AI coding policy & review gates
Standards for what gets AI-generated, what gets human review, and how it gets logged.
Compliance mappingMaps to the OWASP AI Exchange's development-time threat category, the OWASP Agentic Security Top 10's unexpected-code-execution and supply-chain items, the SANS Critical AI Security Guidelines' model-I/O and governance controls for AI-assisted development, and the CSA AI Controls Matrix's Application & Interface Security and Supply Chain Management domains.
Category structure adapted from the AI Defense Matrix by Lenny Zeltser and Sounil Yu, licensed CC BY-SA 4.0. For a broader view of the vendor landscape, see the AI Defense Matrix Catalog.
Not sure AI-Generated Code is your biggest gap? The assessment will tell you.
Take the free assessment →