programming · Level 2
Vibe coding: what it is, what it's good for, and where it breaks
Name the trend honestly, learn where it fits, and build a habit of checking AI-written code before you trust it.

Start with the essentials
The short answer
Vibe coding means describing what you want in plain words and accepting the AI's code with little or no review, a term coined by Andrej Karpathy in February 2025. It suits small, low-stakes, throwaway work. Most developers do not always check AI-written code before using it. This workbook teaches a responsible middle path: a plain checklist, your own test examples, and guardrails that hold regardless.
What you will learn
- You will be able to explain what vibe coding means and place a real example of your own work on the spectrum from careful review to full vibe coding.
- You will be able to describe the trust gap between how much people use AI coding tools and how often they actually check what the tools produce.
- You will be able to judge when vibe coding is a reasonable trade-off and when the stakes call for a full review.
- You will be able to review code you did not write and do not fully understand, using a plain checklist rather than deep language knowledge.
- You will know the guardrails worth keeping every time: what never to paste, where to work, and when to test before you trust the result.
- You will have a short set of personal rules for using AI coding tools responsibly, ready to use on your next real task.
Who it is for
Anyone who uses, or is thinking about using, an AI tool to write code, formulas, macros or scripts, from a complete beginner trying a one-off script to someone building small tools for work. No programming background is assumed.
Before you start
- Some comfort asking an AI assistant for things in plain words, as in the Your first prompts workbook. No coding experience is needed; the examples are explained as they appear.
Read a sample · Chapter 04 of 05
How to review code you don't fully understand yourself
You do not need to read every symbol to review AI-written code well. You need to ask the right questions and test the answers.
You can review code you cannot fully write yourself. The checklist below works whatever the language, because it asks about behaviour, not syntax. Your editor's or notes app's find tool can help you spot the words in the right-hand column even in code you do not read fluently.
Scroll sideways to see every column.
| Ask | Look or ask for |
|---|---|
| What does it touch? | Which files, accounts, folders or data it reads or changes |
| What does it send, and where? | Any email, message, upload or request to another address |
| What happens with bad input? | An empty box, a huge number, the wrong kind of answer |
| Does it match my brief? | Read your own written request back against what it built |
| Can I test it against an answer I already know? | At least one example where you worked out the right result yourself first |
A flawed example, in plain words. An AI was asked to work out a 20% deposit on a booking and refuse any booking of £10 or under. Here is what it actually did, written out step by step rather than as code, so you can review it without reading a line of syntax:
EXAMPLE ONLY. Read it, do not build from it.
1. It reads the booking amount typed into the box.
2. It works out 20 per cent of that amount as the deposit.
3. It emails the customer's address and the booking amount to a logging address, without being asked to.
4. It refuses a booking only when the amount is exactly 10 or under, so a booking of 10.50 is allowed, which is correct, but a booking of 9.99 is also allowed, which should have been refused.
5. If the amount box is left empty, it shows the deposit as NaN (not a number) instead of a clear message.Try it yourself · Activity 04
15 minSpot the four problems
Read the plain-words description of the booking-deposit script above using the checklist.
- Say in your own words what the script is meant to do.
- Using the checklist, find four things wrong with what it actually does.
- For each, write one sentence on how you would ask for it to be fixed.
Which of the four would have been hardest to spot without the checklist?
Worked answer
1. Sending: it emails the customer's address and amount to a logging address nobody asked for, worth removing without a clear, agreed reason. 2. Bad input: an empty box shows NaN instead of a clear message. 3. The brief: a booking of 9.99 should have been refused but was allowed, because the check only catches exactly 10 or under, not anything under 10. 4. Testing: none of this shows up without trying a normal amount, an empty box and an amount right at the 10 line, each checked against a hand-worked answer first.
- Q1: Do you need to read every line of code to review it well?
- A: No. A checklist that asks about behaviour, what it touches, sends, does with bad input and whether it matches your brief, works whatever the language.
- Q2: Why is an AI's own explanation of its code not proof that the code is right?
- A: The explanation is generated the same way the code was, so it can sound fluent and still be wrong. Your own test against an answer you already know is the real proof.
- Q3: What is the single most useful test you can run on AI-written code?
- A: An example where you worked out the correct answer yourself first, then checked the code against it.
- Q4: In the booking example, why did the 10 check cause a problem?
- A: It only caught bookings of exactly 10 or under, so an amount just under that line was wrongly allowed instead of refused.
Keep learning
The complete workbook
This workbook names vibe coding honestly: giving an AI a high-level instruction and shipping what it produces with little review. You will learn where that trade-off is reasonable, how to review AI-written code even when you cannot write it yourself, and the guardrails worth keeping regardless of how good your tools get.
- 01Naming the trend: what vibe coding actually isIn the workbook · 1 exercise
Vibe coding has a name, a real origin and a real trade-off. Knowing all three stops the word being either a compliment or an insult.
- 02The real trust gapIn the workbook · 1 exercise
Almost everyone uses these tools now. Hardly anyone fully trusts what they produce, and fewer still check it every time. That gap is the whole reason this workbook exists.
- 03When vibe coding is a reasonable choice, and when it isn'tIn the workbook · 1 exercise
The right question is never whether vibe coding is good or bad, it is what happens if this particular piece is wrong.
- 04How to review code you don't fully understand yourselfRead here · 1 exercise
You do not need to read every symbol to review AI-written code well. You need to ask the right questions and test the answers.
- 05Guardrails to keep, and a workflow you'll actually useIn the workbook · 1 exercise
A handful of habits turn vibe coding from a gamble into a reasonable, repeatable way of working.
Also inside: a 10-point checklist, a glossary of 10 terms and 10 questions and answers to test yourself. 5 hands-on exercises, each with a worked answer at the back where the workbook gives one.
No login, no card, no account. Before the download we ask you to follow Mickai (two quick links). Free to download and use for personal learning, study groups and inside your own team. Please do not resell the workbooks or republish them as your own. Link people to trust-agent.ai instead.
Test yourself
Questions and answers
What is vibe coding?
Vibe coding means describing what you want in plain words and accepting the AI's code with little or no line-by-line review. The term was coined by Andrej Karpathy in a widely shared post in February 2025. It sits at one end of a spectrum that runs from approving one suggestion at a time to never opening the file at all.
Is vibe coding always a bad idea?
No. On a low-stakes prototype you would happily throw away, it can be a fair trade-off. The real question is not whether vibe coding is good or bad, it is what would happen if this exact piece of code were quietly wrong.
How many developers actually trust AI-written code?
Stack Overflow's 2025 Developer Survey found 84% of developers use or plan to use AI tools, but only 29% trust the accuracy of what those tools produce and 46% actively distrust it. Use has grown far faster than trust.
Do most developers check AI-written code before using it?
Not always. Sonar's State of Code developer survey found only 48% of developers said they always verified AI-assisted code before committing it, meaning most ship at least some of it unchecked, at least some of the time.
How do I decide whether a task is safe to vibe code?
Ask what would happen if this exact piece of code were quietly wrong: can you undo it, does it touch money or personal data, does anyone else rely on it, and how would you even notice a mistake? The higher the stakes, the more it deserves a full review.
Do I need to understand code deeply to review it?
No. A checklist that asks about behaviour, what the code touches, sends, does with bad input, and whether it matches your brief, works whatever the language, without you needing to read every symbol.
If an AI explains its own code, does that prove the code is right?
No. The explanation is produced the same way as the code, so it can sound fluent and still be wrong. Testing the result against an example you worked out yourself first is the real proof.
What should I never paste into an AI coding tool?
Passwords, keys, account numbers or other people's personal details. Use made-up example data instead, and if a real secret slips in by mistake, treat it as exposed and replace it where it was issued.
What is a dry run, and why does it matter?
A dry run is a list of what a tool would do without actually doing it. Asking for one before anything that changes real files or sends anything lets you check the plan while it still costs nothing to change your mind.
What is the single most useful habit for catching a quiet AI coding mistake?
Testing the result against an example you worked out by hand yourself, rather than trusting the tool's own account of what it did. It is the one step that catches a wrong answer even when everything looks fine.
When you have finished
Get your certificate of completion
Type your name and download a certificate for this workbook as a PDF, ready to print or to add to LinkedIn. It is made on your own device, so your name is never sent to us. It is a self-declared certificate, not an accredited qualification.
Learn the language
Key terms
- Vibe coding
- Describing what you want in plain words and accepting the AI's code with little or no line-by-line review.
- Trust gap
- The distance between how much people use AI coding tools and how often they actually check what those tools produce.
- Code review
- Reading and checking code, your own or an AI's, before you trust or run it.
- Hallucination
- A confident answer that is wrong or unfounded, such as code that behaves as if a library, function or rule exists when it does not.
- Blast radius
- How much damage a mistake could do and how hard it would be to undo, used here to judge how carefully a task needs reviewing.
- Sandbox
- A working copy or a set-aside folder where an AI tool can make changes without touching your real files.
6 of the workbook's 10 terms. The complete glossary is in the workbook.
Follow the evidence
Sources and checks
Facts last checked: .
These workbooks use AI assistance. See how the workbooks are made.
- There's a new kind of coding I call vibe codingAndrej Karpathy, posted on X
- 2025 Stack Overflow Developer Survey: AIStack Overflow
- State of Code: the current reality of AI codingSonar
- The 'vibe coding spectrum' approach to AI-assisted software developmentNational Cyber Security Centre (NCSC)
- LLM02:2025 Sensitive Information DisclosureOWASP Gen AI Security Project
- LLM06:2025 Excessive AgencyOWASP Gen AI Security Project
- LLM09:2025 MisinformationOWASP Gen AI Security Project
- How copyright protects your work: OverviewGOV.UK
Created by Mickarle Wagstaff-Irons - Micky Irons with the Mickai team. Published by Mickai LTD. Last updated 29 September 2026.
NextKeep going
Where to go next
Recommended for you
Build your first app with an AI coding assistant
Build a small bill-splitting web page with any AI coding assistant while staying in control: brief it, build in steps, review the code, test edge cases and keep safe copies.
Recommended for you
Test-driven development with an AI coding assistant
Use failing examples to guide an AI coding assistant, test boundary cases, catch deliberate defects and hand over a small Python change with clear evidence.
Recommended for you
Git for AI builders: commits, branches and pull requests
Learn Git from your first commit to a reviewed pull request, with safe habits for AI-written code: read every diff, commit small, undo safely and keep secrets out.