Previous Next
0 / 3

Module questions

VC-07 ยท Quality, Security, and Performance

Module VC-07VIBECODE

Scan Configuration for Secrets

VIBECODE โ€ข Vibe Coding: AI-First Software Delivery

Browser-only practice

Problem Statement

Stage: Quality, Security, and Performance

An AI-generated patch may have embedded credentials.

Deliverable

Line-numbered suspected secret keys.

Input and output contract

Read KEY=value lines; flag non-empty keys containing token, password, secret, or api_key; print PASS when clean.

Acceptance criteria

  1. Match key names case-insensitively.
  2. Do not flag empty values.
  3. Never print secret values.

Suggested vibe loop

Read AGENTS.md, connect your Ollama or OpenAI-compatible provider in the browser, and ask the agent to restate the contract and make one small verifiable change. Watch edits stream into app.py while the editor is locked, then review the result and run the visible example. Keep the checkpoint when the evidence is correct or use Undo to restore it. The browser-client agent does not require an administrator gateway or API key.

Constraints

Use Python 3 standard library only. Read and follow AGENTS.md, keep main.py as the entry point, and implement solve(raw) in app.py.

Sample Testcases

Submit runs every public testcase in this browser. Results and code never leave this device.

Sample #1
Public sample
APP_ENV=local
API_TOKEN=abc123
DB_PASSWORD=hunter2
LINE 2: API_TOKEN
LINE 3: DB_PASSWORD
Finds secrets without exposing values.

Web terminal

C, C++, Java, and Python run locally in a browser VM. No worker or visualizer is used.

Saved in this browser
Editor settings