Vercel's CEO Wants the Compiler to Catch Your AI Agent's Missing Auth Check — Make Security Rules Machine-Enforced

Vercel's CEO Wants the Compiler to Catch Your AI Agent's Missing Auth Check — Make Security Rules Machine-Enforced

2026-10-06

On October 5, Guillermo Rauch, CEO of the web hosting company Vercel, released gdp-ts, an open-source tool that makes the code itself refuse to compile when a sensitive action skips its permission check (Guillermo Rauch on X).

His reason is the headline for every operator: “Agents are writing more code than we can review, and they thrive in tight loops with hard constraints that would frustrate us.”

The takeaway: if AI is writing a growing share of your code, your most important security rules cannot live in a reviewer’s head. They need to live somewhere a machine checks on every build.

What gdp-ts does, in plain words

Most apps protect sensitive actions, like deleting a project or changing a password, with an authorization check: code that confirms this user is allowed to do this thing. The classic bug is simple. Someone adds a new path to that action and forgets the check.

gdp-ts works with TypeScript, a popular version of JavaScript that adds a “type checker,” a tool that inspects code for mistakes before it ever runs. With gdp-ts, a sensitive function demands a “proof” that the permission check already happened for that exact user and that exact resource. No proof, no build. Rauch describes it as “a library, linter and AI skill,” meaning it ships as code you import, an automated style checker, and a set of instructions coding agents can follow (Guillermo Rauch on X).

The project’s example mirrors a real Vercel rule: changing the password on a project requires proof of a certain role plus a certain entitlement (Guillermo Rauch on X). The real permission lookup still happens when the code runs. gdp-ts just makes it impossible to call the sensitive function without having done it.

This is an old idea finally getting its moment

The pattern comes from Haskell, a programming language popular with researchers, and is named after “Ghosts of Departed Proofs,” a 2018 paper by Matt Noonan. Rauch credits Noonan and Haskell developer Ollie Charles for the research. His argument is that the approach stayed niche because it added work for humans: extra syntax to write and extra code to review. Now the cost lands on agents, and agents do not mind (Guillermo Rauch on X).

That logic holds well beyond one library. The more code a machine writes, the cheaper strict rules become and the more expensive “we’ll catch it in review” gets.

Why this bug class deserves the attention

This is not a niche worry. Broken access control, meaning users reaching data or actions they should not, is ranked number one in the OWASP Top 10:2025, the widely used list of web app security risks from the nonprofit Open Worldwide Application Security Project. OWASP says it has the most occurrences of any category in its data (OWASP).

Now picture that bug class meeting a coding agent that ships twenty pull requests a day. Your reviewer gets tired by PR number six. The type checker does not.

A five-step plan for owners, operators, and engineering leads

  1. List your crown-jewel actions. Write down the ten or so operations that would hurt most if the wrong person triggered them: billing changes, data exports, role changes, deletes, password resets. Start there, not everywhere.
  2. Put the real checks in one small, trusted place. Permission logic scattered across a codebase is how checks get forgotten. Centralize it in a small module that humans review carefully. Everything else, including agent-written code, has to go through it.
  3. Make the build fail, not the reviewer. Whether you use gdp-ts, your language’s type system, or custom lint rules, the goal is the same: a missing check should break the build in CI (the automated pipeline that tests every change), not wait for someone to notice.
  4. Tell your agents the rules. Coding agents follow written instructions. Put your security patterns in the project’s agent instruction files so the agent writes code the right way the first time.
  5. Keep your runtime safety net. Compile-time checks do not replace tests, logging, or a security review of the trusted module. They shrink the space where mistakes can hide.

One caution: gdp-ts is days old and published under Rauch’s personal GitHub account, not as a Vercel platform product. Review it like any new dependency before you bet production on it.

Soft next step

The bottleneck in AI-assisted development is no longer writing code. It is trusting it. Turn your most important security rules into checks a machine runs every time, and save human review for the parts that genuinely need judgment.

Yellow Coop helps owners and operators set guardrails for AI coding agents, audit access control, and build a review process that scales with agent output — including a clear answer on who owns application security. See our track record, or start at contact.

Internal links: Secure, What We Do, How We Engage, CIO vs CTO vs CISO, Track Record, Insights.

Sources