Loading video...
Video Failed to Load
You can now run black-box pen tests for your Replit apps. Security scans that test your Replit apps the way external attackers do. Replit Agent can fix what it finds in a single click.
147,048 views • 1 month ago •via X (Twitter)
23 Comments

Combine this with white-box tests. These scans assess your code from the inside to find vulnerabilities. Your built-in security team on Replit.

Building your own software shouldn’t mean compromising on security. At Replit, we give you the best of both worlds. Read more at

Black-box pen testing built-in? Security just leveled up

That's huge one-click fixes game changer

whoa this is major

That's nice. Being able to test applications from the outside the way an attacker sees them and then fix those vulnerabilties is a great security freature.

agent can fix what it finds in one click it also shipped it in one click

Wait… so it can actually find vulnerabilities the way an external attacker would? 👀 Kinda curious how deep these scans can go.

One click security scans is so handy

amazing!

Ship faster and sleep better security handled.

Black-box testing plus one-click fixes is the right loop. Security guidance without remediation usually dies in a backlog.

Makes sense for the platform model. Security built into the IDE removes the excuse of it being someone else's problem. I'd want to see how the Agent handles edge cases, not just surface-level patches.

Very cool. Does the agent rerun the same black-box test after the fix, or is that still on the human?

This is a huge improvement to vibe coding security. Well done!

This is the right loop: detect the failure, preserve the evidence, fix it, then verify the fix. The last step matters most. An agent that reports “resolved” without a second adversarial check is automation, not assurance.

Code security just went up a whole level

@Replit keeps shipping and I'm genuinely impressed every single time

The black-box angle is useful because it tests the app the way a user or attacker actually meets it. I would also want the fix path to leave a clear receipt: what the scan found, what changed, and what still needs a human check after the one-click repair.

Black-box testing plus one-click remediation makes app security far more practical

Replit Agent pen-testing your app, finding 40 critical vulnerabilities, and then fixing them all by deleting the codebase: 🗿

That's huge Black box pen tests + one click fixes on Replit is security made actually easy for builders

Security agent is a good step. Next useful layer is stopping the agent from rewriting the same auth/security patterns from first principles every single time. Made a small system for that exact problem (structured mutations the agent can just invoke). Happy to share the approach.

