<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" 
  xmlns:content="http://purl.org/rss/1.0/modules/content/" 
  xmlns:dc="http://purl.org/dc/elements/1.1/" 
  xmlns:atom="http://www.w3.org/2005/Atom" 
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
  xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>Cursor on ✏VictorHong&#39;s Blog</title>
    <link>https://hugo.jiahongw.com/tags/cursor/</link>
    <description>Recent content in Cursor on ✏VictorHong&#39;s Blog</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>zh</language>
    <follow_challenge>
        <feedId>74349588616178697</feedId>
        <userId>68207800989737984</userId>
    </follow_challenge>
    <managingEditor>wujiahong2013@gmail.com (VictorHong)</managingEditor>
    <webMaster>wujiahong2013@gmail.com (VictorHong)</webMaster>
    <copyright>©2021-2026 | VictorHong</copyright>
    <lastBuildDate>Thu, 14 May 2026 01:00:00 +0800</lastBuildDate>
    
        <atom:link href="https://hugo.jiahongw.com/tags/cursor/index.xml" rel="self" type="application/rss+xml" />
    

      
      <item>
        <title>Vibe Coding 安全危机：48 个应用扫描揭露的惊人真相</title>
        <link>https://hugo.jiahongw.com/20260514/vibe-coding-security-crisis-48-apps-scanned/</link>
        <pubDate>Thu, 14 May 2026 01:00:00 +0800</pubDate>
        <author>wujiahong2013@gmail.com (VictorHong)</author>
        <atom:modified>Thu, 14 May 2026 01:00:00 +0800</atom:modified>
        <guid>https://hugo.jiahongw.com/20260514/vibe-coding-security-crisis-48-apps-scanned/</guid>
        <description>&lt;h2 id=&#34;核心观点&#34;&gt;核心观点&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Vibe Coding 正在制造一场安全危机。&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;2026 年 5 月，Reddit 用户 u/Powerful-Fly-9403 发布了一份震撼开发社区的安全审计报告：他们对 48 个使用 Lovable、Bolt、Replit 等 AI 编程工具生成的应用进行扫描，发现 &lt;strong&gt;90% 存在至少一个安全漏洞&lt;/strong&gt;，44% 存在认证绕过问题，33% 使用了危险的 PostgreSQL &lt;code&gt;SECURITY DEFINER&lt;/code&gt; 函数，25% 存在 BOLA/IDOR 访问控制漏洞。&lt;/p&gt;
&lt;p&gt;这不是危言耸听。Georgia Tech 的研究团队同期发布的 &lt;a href=&#34;https://vibe-radar-ten.vercel.app/&#34;&gt;Vibe Security Radar&lt;/a&gt; 数据显示，2026 年第一季度已确认 56 个与 AI 生成代码相关的 CVE 漏洞，仅 3 月份就发现了 35 个，超过 2025 年全年的总和。&lt;/p&gt;
&lt;p&gt;当开发者沉浸在&amp;quot;几分钟生成一个应用&amp;quot;的快感中时，安全债务正在以指数级速度累积。&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://cos.jiahongw.com/rss-daily/20260514/img-01.png&#34; alt=&#34;安全扫描概念图&#34; /&gt;&lt;/p&gt;</description>
        
        <dc:creator>VictorHong</dc:creator>
        <media:content url="https://hugo.jiahongw.comhttps://cos.jiahongw.com/rss-daily/20260514/cover.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>Vibe Coding</category>
            
          
            
              <category>AI安全</category>
            
          
            
              <category>代码审计</category>
            
          
            
              <category>网络安全</category>
            
          
            
              <category>Claude</category>
            
          
            
              <category>Cursor</category>
            
          
        
        
          
            
              <category>技术</category>
            
          
            
              <category>安全</category>
            
          
        
        
      </item>
      
      <item>
        <title>blog_post</title>
        <link>https://hugo.jiahongw.com/daily/blog_post/</link>
        <pubDate>Wed, 13 May 2026 18:49:28 +0800</pubDate>
        <author>wujiahong2013@gmail.com (VictorHong)</author>
        <atom:modified>Wed, 13 May 2026 18:49:28 +0800</atom:modified>
        <guid>https://hugo.jiahongw.com/daily/blog_post/</guid>
        <description>&lt;h1 id=&#34;x-following-digest---2026-05-13&#34;&gt;X Following Digest - 2026-05-13&lt;/h1&gt;
&lt;p&gt;生成时间：2026-05-13 10:40:33 UTC&lt;br /&gt;
筛选范围：最近 24 小时&lt;br /&gt;
精选推文数：12&lt;/p&gt;</description>
        
        <dc:creator>VictorHong</dc:creator>
        
        
        
        
          
            
              <category>AI</category>
            
          
            
              <category>Claude</category>
            
          
            
              <category>Anthropic</category>
            
          
            
              <category>Go</category>
            
          
            
              <category>Cursor</category>
            
          
            
              <category>AI</category>
            
          
            
              <category>Daily Digest</category>
            
          
        
        
          
            
              <category>技术</category>
            
          
            
              <category>AI</category>
            
          
        
        
      </item>
      
      <item>
        <title>Cursor 3 强势登场：AI 编程工具三国大战全解析</title>
        <link>https://hugo.jiahongw.com/20260403/cursor3-vs-claude-code-codex/</link>
        <pubDate>Fri, 03 Apr 2026 01:12:46 +0800</pubDate>
        <author>wujiahong2013@gmail.com (VictorHong)</author>
        <atom:modified>Fri, 03 Apr 2026 01:12:46 +0800</atom:modified>
        <guid>https://hugo.jiahongw.com/20260403/cursor3-vs-claude-code-codex/</guid>
        <description>2026年4月2日，Cursor 正式发布 Cursor 3（代号 Glass），一款将 AI Agent 完全融入开发环境的革命性产品。这不仅是 Cursor 的产品迭代，更是 AI 编程工具</description>
        
        <dc:creator>VictorHong</dc:creator>
        <media:content url="https://hugo.jiahongw.comhttps://cos.jiahongw.com/rss-daily/20260403/cover.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>AI</category>
            
          
            
              <category>编程工具</category>
            
          
            
              <category>Cursor</category>
            
          
            
              <category>Claude Code</category>
            
          
            
              <category>Codex</category>
            
          
        
        
          
            
              <category>AI编程</category>
            
          
            
              <category>技术趋势</category>
            
          
        
        
      </item>
      
      <item>
        <title>Pencil 最佳实践：IDE 内设计到代码的完整工作流</title>
        <link>https://hugo.jiahongw.com/20260311/pencil-best-practices/</link>
        <pubDate>Wed, 11 Mar 2026 17:25:00 +0000</pubDate>
        <author>wujiahong2013@gmail.com (VictorHong)</author>
        <atom:modified>Wed, 11 Mar 2026 17:25:00 +0000</atom:modified>
        <guid>https://hugo.jiahongw.com/20260311/pencil-best-practices/</guid>
        <description>概述 Pencil 是一个嵌入 IDE 的矢量设计工具，支持在 VS Code/Cursor 中直接绘制 UI 设计稿，并通过 AI 自动生成代码，还能实现设计与代码的双向同步。本文从核心定位到实战配置</description>
        
        <dc:creator>VictorHong</dc:creator>
        <media:content url="https://hugo.jiahongw.comhttps://openclaw.cos.jiahongw.com/blog/pencil-best-practices-cover.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>Pencil</category>
            
          
            
              <category>设计工具</category>
            
          
            
              <category>AI编程</category>
            
          
            
              <category>VS Code</category>
            
          
            
              <category>Cursor</category>
            
          
            
              <category>Design Token</category>
            
          
            
              <category>设计到代码</category>
            
          
        
        
          
            
              <category>AI编程</category>
            
          
        
        
      </item>
      

    
  </channel>
</rss>