What is your developer-dependent CMS actually costing you? Calculate your costs and get a full report
What is your developer-dependent CMS actually costing you? Calculate your costs and get a full report
Vibe Coding
What a vibe-coded Agility proof of concept skips that production needs: webhook signature verification, secrets, caching, preview security, accessibility, tests, observability, governance, performance and current defaults.
A vibe-coded proof of concept is built to answer one question: can this work, for this use case, on Agility? It's allowed to cut corners to get there. Production isn't. This article lists what a proof of concept typically skips and what to put back before real users or real data arrive.
If you followed the vibe coding workflow, your handoff notes already list what's simulated and what was left out. Start from that list, then work through the sections below. The general Website Deployment Checklist applies too.
Your publish webhook endpoint is a public URL. Without a signature check, anyone who finds it can post to it and trigger revalidation, or anything else the handler does.
This is the shortcut most worth looking for. In the builds behind this section, at least two proofs of concept switched off the webhook's secret check to get a demo working. The Agility Next.js Starter's revalidate route doesn't check a signature by default either.
Proofs of concept often mock sign-in, membership lookups, search indexes, inventory feeds or analytics. For each mocked piece in your handoff notes, decide whether it's in scope, and replace it with the real integration or remove it. Gated content in particular needs real authentication and authorization before any of it is genuinely private.
Replace invented sample content too. If you kept a content provenance file, it lists exactly which items were copied, rewritten or invented.
Automated checks (Lighthouse, axe, contrast checkers) catch a useful share of problems, but they are not a WCAG audit. Before launch:
A proof of concept usually has none. Add at least:
npm run build type-checks and prerenders every page in the sitemap).During a proof of concept the AI tool often creates and publishes content freely. In production, decide deliberately:
Set budgets for page weight, JavaScript, images and Core Web Vitals, and check them in CI. Watch for demo-era shortcuts: unoptimized images, large client components that could be server components, and third-party scripts added for the demo.
Proofs of concept are often started from whatever was on hand. Before production, bring the stack up to current defaults:
Also clean out leftovers: if the project was copied from an earlier build, search for the previous project's names, components, environment variables and copy.