KBAISE/ for lovable
Library
Docs

Run AI-powered penetration tests with Aikido

about 30 minBuildingchecked 15h agoOfficial page
The short version

You can use Aikido to run AI-powered penetration tests on your Lovable projects. This helps find real security weaknesses by simulating attacks, and generates reports for compliance.

Anyone building software with Lovable who needs to find exploitable security vulnerabilities or generate security reports for compliance.

Do this, in order

  1. 1

    Go to 'Connectors' in your Lovable workspace settings and select 'Aikido'.

    This is the first step to link your Lovable workspace with your Aikido account.

  2. 2

    Click 'Add connection', give it a name like 'Aikido', then click 'Connect' and authorize the connection in the pop-up window.

    This establishes the secure link between Lovable and Aikido, allowing them to work together.

  3. 3

    Open your project, go to 'Security view', then 'Agentic penetration test by Aikido', and click 'Prepare Aikido pentest' or 'Launch new pentest'.

    This starts the process of setting up a new security test for your specific project.

  4. 4

    Acknowledge the warning about database changes, then Lovable will send your project to Aikido and open a pre-configured assessment there.

    This prepares your project for testing and transfers necessary information to Aikido.

  5. 5

    In Aikido, add at least one test user with a username and password in the 'Authentication instructions' field, then click 'Save and Test'.

    Providing test user credentials allows Aikido to test parts of your application that require a user to be logged in, finding more vulnerabilities.

  6. 6

    Review the pre-filled configuration in Aikido (adjusting if needed, but usually not required), then click 'Run Assessment' and confirm to launch the test.

    This starts the actual AI-powered security test on your project.

  7. 7

    Once the pentest is complete, go back to your project's 'Security view' in Lovable and click 'Sync findings'.

    This pulls the results of the security test from Aikido into your Lovable project, showing you the identified issues.

  8. 8

    To fix an issue, copy the attack analysis from Aikido into your project chat, or click 'Try to fix all' to have Lovable attempt a fix.

    This helps you address the security weaknesses found by the test.

  9. 9

    To check if a fix worked, use the 'Retest issue' option in Aikido, then sync findings again in Lovable.

    This verifies that your changes have successfully resolved the vulnerability.

  10. 10

    Access and download the automatically generated pentest report from Aikido.

    This report is useful for sharing with customers, investors, or for compliance requirements like SOC 2 or ISO 27001.

Paste this into your project

Hey Lovable, I need to run an AI-powered penetration test on my project using Aikido. Please help me connect Aikido to my workspace and then launch a new pentest for my current project. I've already created a dedicated test user for Aikido to use.

Words decoded

AI-powered penetration testing
Using artificial intelligence to simulate real attacks on your software to find security weaknesses, just like a human hacker would.
Dynamic analysis
Testing your software by actually running it and interacting with it, like a user would, to see how it behaves and if it has any security flaws.
Static analysis
Checking your software's code without running it, looking for known patterns or mistakes that could lead to security problems.
Vulnerabilities
Weaknesses in your software that could be exploited by an attacker to cause harm, like stealing data or taking control.
Exploitable vulnerabilities
Security weaknesses that an attacker can actually use to break into or harm your system, not just theoretical problems.
Blackbox testing
Testing your software without knowing anything about its internal workings, just like an external attacker would.
Whitebox testing
Testing your software with full knowledge of its internal code and design, allowing for a deeper check for flaws.
OAuth
A secure way for one service (like Lovable) to get permission to access information or perform actions on another service (like Aikido) on your behalf, without sharing your password.
SOC 2, ISO 27001
Common security standards and certifications that businesses often need to meet to prove they handle data securely.

Where people get stuck

  • Not having a paid Aikido account, as pentests are billed through Aikido.
  • Not having Lovable workspace admin/owner role to connect Aikido, or editor/higher role to run pentests.
  • Forgetting to create a dedicated test user account with username and password for Aikido to test authenticated parts of your application.
  • Blocking pop-ups in your browser, which will prevent the Aikido authorization window from opening during connection.
  • Expecting findings to sync automatically; you must manually click 'Sync findings' in Lovable after the pentest completes.
  • Not reviewing the pre-filled configuration in Aikido, especially the test user credentials, before launching the assessment.

The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.