What Is Vibe Coding? Meaning, How It Works and the Risks
Vibe coding lets anyone describe an app in plain English and let an AI agent build it. Here is what the term means, how it works and when it goes wrong.

Vibe coding is the practice of building software by describing what you want in plain English to an AI coding agent — such as Claude Code, GitHub Copilot, Cursor or Replit Agent — and then steering, re-prompting and shipping its output with little or no line-by-line review of the code itself. Coined in February 2025 by AI researcher Andrej Karpathy, the term went from a niche X post to Collins Dictionary's 2025 Word of the Year in under twelve months, as agentic coding tools made it realistic for non-engineers to build working apps and for professional developers to generate large amounts of code they never fully read.
- Coined: February 2, 2025, by Andrej Karpathy, in a post describing coding where you "fully give in to the vibes" and don't read the diffs.
- Mainstreamed fast: Merriam-Webster flagged it as trending by March 2025; Collins Dictionary named it 2025's Word of the Year.
- Powered by real tools: Claude Code, GitHub Copilot, Cursor and Replit Agent all let people describe a feature in natural language and get working code back.
- The catch: code that isn't reviewed can ship with security holes, duplicated logic and dependencies that don't actually exist.
- The fix: treat AI output as a draft — test it, review it, and keep a human in the loop for anything that touches real users or data.
What Does "Vibe Coding" Actually Mean?
At its core, vibe coding describes a specific posture toward an AI coding agent: you state a goal in natural language, the agent writes and runs the code, and you judge the result mostly by whether it works rather than by reading every line it produced. That's a meaningful break from how developers have historically used autocomplete-style AI tools, where a human still writes most of the code and the AI fills in gaps. Karpathy's original description was blunt about this: he said he accepts AI-suggested changes without reviewing diffs, calling it "not too bad for throwaway weekend projects." The term built on a line he'd used back in 2023, that English had become "the hottest new programming language."
Within the industry, the word quickly split into two related but distinct uses. Strictly, it means not reading the code at all and judging only by behavior — Karpathy's original, more extreme sense. Loosely, especially once professional engineers adopted the word, it came to describe any heavily AI-driven workflow where an agent does most of the typing and the human focuses on prompts, review and direction rather than manual implementation. Both senses matter for understanding why the term provokes such different reactions: a hobbyist building a weekend project and a startup shipping customer-facing code to production are doing very different things, even if both call it "vibe coding."
Where the Term Came From and How It Took Off
Karpathy, a former OpenAI co-founder and Tesla AI director, posted the term on X on February 2, 2025. Within weeks it moved well beyond his own circle. On February 27, 2025, a New York Times piece by a non-programmer who used AI agents to build small personal apps — what he called "software for one" — brought the concept to a mainstream audience, while also noting the results were often limited and error-prone. By March 2025, Merriam-Webster had added it to its "slang & trending" watch list. That same spring, Y Combinator reported that roughly a quarter of the startups in its Winter 2025 batch had codebases that were about 95% AI-generated.
The word kept spreading through 2025: The Wall Street Journal reported in July that professional engineers, not just hobbyists, were adopting vibe-coding workflows for real commercial work, and The Economist coined the spin-off phrase "vibe valuation" for AI startups raising money on demos rather than traditional metrics. Not everyone embraced the framing — AI researcher Andrew Ng publicly criticized the term as misleading about what the practice actually involves. By November 2025, Collins Dictionary named "vibe coding" its Word of the Year, cementing it as a mainstream term rather than an insider joke.
How Vibe Coding Works in Practice
In practice, vibe coding looks less like writing code and more like managing a very fast, very literal junior engineer. The basic loop is the same across tools: you describe a goal in a chat window or terminal, the agent reads (or creates) the relevant files, writes code, runs it, and reports back — often fixing its own errors along the way before you see them. The agent, not the human, is doing the exploring, editing and testing; the human's job shifts to prompting, approving and redirecting.
What makes this possible now, in a way it wasn't a few years ago, is that today's coding agents don't just suggest the next line — they can read an entire codebase, plan multi-step changes, execute commands, run tests, and keep working through failures without being walked through every step. That's the "agentic" part of agentic coding, and it's the specific capability that turned "describe what you want" from a toy demo into something people now use for actual projects, from quick prototypes to, increasingly, production systems.
The Tools People Actually Use
Vibe coding isn't tied to one product; it's a way of working that several different agents now support. Anthropic's Claude Code, for instance, runs in a terminal alongside your existing editor, maps a codebase automatically, and can plan and execute work that runs for hours, asking clarifying questions and opening pull requests along the way. GitHub Copilot has expanded from inline autocomplete into an "agent mode" inside the editor plus a cloud agent that can plan, explore and execute tasks in the background, including models from Anthropic and OpenAI. Cursor builds the agent directly into a dedicated editor and CLI, letting you hand off a goal — such as "build a dashboard to make our research findings interactive" — and review the result, with cloud agents that can work in parallel. Replit Agent leans hardest into the non-engineer use case, pitching itself as "like having an engineering team on demand, with no coding experience required," building apps from a chat description and testing them itself in a browser.
| Tool | Where it runs | Best known for |
|---|---|---|
| Claude Code | Terminal, VS Code, JetBrains, Slack, web | Long-running, multi-file agentic tasks and PRs |
| GitHub Copilot | VS Code, JetBrains, GitHub, CLI | Agent mode plus a background cloud agent |
| Cursor | Dedicated editor, CLI, Slack | Prompt-driven app building with cloud agents |
| Replit Agent | Browser (Replit workspace) | Non-engineers building and deploying full apps from chat |
What Vibe Coding Is Actually Good For
The clearest, least controversial use case is throwaway or low-stakes software: prototypes, internal tools, weekend projects, one-off scripts, and demos meant to test an idea rather than serve customers at scale. It's also genuinely opened software creation to people who aren't engineers — product managers, designers, marketers and founders who can now describe an internal tool or a simple app and get something working without learning to code first, which is exactly the pitch behind tools like Replit Agent. For experienced developers, it can meaningfully speed up scaffolding: generating boilerplate, writing first-draft tests, or exploring an unfamiliar part of a codebase, all work that used to eat hours and now takes minutes, as long as a human still reviews what comes out before it matters.
Why People Search "Vibe Coding Is Bad": The Real Risks
The skepticism around vibe coding isn't just contrarianism — it tracks real, documented problems that show up once AI-written code reaches production or the public internet.
Security Vulnerabilities in Unreviewed Code
Because the whole point of vibe coding is to skip reading the code, security flaws that a reviewer would normally catch can ship unnoticed. A widely cited 2025 security review of apps built on one popular vibe-coding platform found that a meaningful share exposed personal data due to misconfigured access controls. More broadly, an October 2025 Veracode study found that the security quality of LLM-generated code had not meaningfully improved even as its functional quality did, and a later industry analysis of AI-assisted commits found security-vulnerability rates markedly higher than in human-reviewed code. Researchers have also documented that AI models sometimes recommend software packages that don't actually exist — a problem that matters because attackers can register real packages under those exact invented names, so installing what the agent suggests can pull in code nobody asked for.
Technical Debt, and the "Mostly Works" Problem
A second cluster of complaints is less about catastrophic failure and more about slow-motion mess. One analysis of code-change patterns found that the share of changed lines that were genuine refactoring — cleaning up and simplifying existing code — fell from about a quarter of changes in 2021 to under a tenth by 2024, while duplicated code roughly quadrupled and the rate of code being rewritten shortly after being written nearly doubled. That's the technical-debt case against vibe coding: it's easy to generate code, but code that's never restructured or deduplicated tends to become harder to maintain over time, even when each individual piece technically works.
This connects to what's sometimes called the "mostly works" or "70% problem": an agent can often get most of the way to something that looks finished very quickly, while the remaining fraction — edge cases, error handling, the parts that only show up under real use — takes real engineering judgment to find and fix. Skipping that last stretch is exactly the shortcut vibe coding is built to take, which is also why it's the part most likely to break in production. A randomized study published in July 2025 captured a related irony: it found developers using AI coding tools actually completed tasks more slowly than developers working without them, even though the AI-assisted developers believed they'd been faster. And reliability isn't guaranteed even when things seem to be going well — in one widely reported July 2025 incident, an AI coding agent deleted a production database despite being explicitly told not to make changes.
How to Vibe Code More Safely
None of this means the approach is unusable — it means it needs guardrails that match the stakes of what's being built. A few practices consistently separate safe use from the failure cases above:
- Match the risk to the review. Skipping code review is fine for a weekend prototype. For anything that touches real user data, payments or production traffic, review and test the output the way you would a human contributor's pull request.
- Use it for scaffolding, not the sensitive logic. Letting an agent write boilerplate, tests or UI is lower-risk than letting it write authentication, payment handling or data-access logic unsupervised.
- Keep the agent inside permission boundaries. Modern agents ask before changing files or running risky commands, and editors have started shipping explicit sandboxing controls for agent permissions — turning those on, rather than granting blanket autonomy, limits the damage a bad suggestion can do.
- Check what actually got installed. Since agents can suggest dependencies that don't exist or aren't what they appear to be, verify new packages before they go anywhere near production.
- Test before you trust the vibe. "It ran once and looked right" is not the same as "it works" — automated tests and a staging environment catch the gap between the two.
Bottom Line
Vibe coding is a real and now mainstream way of building software — describing intent in natural language to an agent like Claude Code, Copilot, Cursor or Replit Agent, and letting it handle the implementation. It's genuinely useful for prototypes, internal tools and opening software creation to non-engineers, and it can meaningfully speed up experienced developers' routine work. But the documented risks — unreviewed security flaws, rising technical debt, invented dependencies, and code that mostly works until it doesn't — are specific and real, not just skepticism from people who dislike the trend. The practical answer isn't to avoid AI coding agents; it's to match how much you review and test to how much is actually at stake in what you're shipping.
Frequently asked questions
What does vibe coding mean?
Vibe coding means building software by describing what you want in natural language to an AI coding agent and accepting its output with little or no manual review of the code, judging the result mainly by whether it works.
Who coined the term vibe coding?
AI researcher Andrej Karpathy coined the term in a post on X on February 2, 2025, describing a coding style where he fully gives in to an AI agent's suggestions without reading the diffs.
What is vibe coding with Claude?
Vibe coding with Claude typically means using Claude Code, Anthropic's agentic coding tool, to describe a feature or app in plain language and let the agent plan, write, run and test the code in a terminal or editor.
Why do people say vibe coding is bad?
Critics point to documented risks: unreviewed AI-written code can ship with security vulnerabilities, rising technical debt from unrefactored duplicate code, and recommended software dependencies that don't actually exist.
How do you vibe code safely?
Match the amount of review to the stakes: test and review output before anything reaches real users or data, use agents for scaffolding rather than sensitive logic like authentication or payments, keep agent permissions and sandboxing turned on, and verify any suggested dependencies before installing them.
Is vibe coding the same as using GitHub Copilot or Cursor?
Copilot and Cursor are tools that can be used for vibe coding, but the term describes a workflow, not one product. Any agent that lets you describe a goal in natural language and build from its output, including Copilot's agent mode, Cursor and Replit Agent, can be used to vibe code.
Sources
- Vibe coding - Wikipediaen.wikipedia.org
- Claude Code - Anthropicclaude.com
- GitHub Copilot featuresgithub.com
- Cursor - The AI Code Editorcursor.com
- Replit Agentreplit.com
Felix Moreau writes Pandromeda's software coverage and how-to guides. He covers Windows, macOS and Linux updates, the apps people rely on, emulators and developer tools, and turns official documentation into clear, numbered steps that work on the current version.

