Jrockowitz iconJrockowitzSep 24, 2026 ~7 min source read

Vibing Drupal: How Jacob Rockowitz used Codex to work through 20+ Webform security issues

A practical account of maintaining Drupal’s Webform module, how AI-assisted workflows helped reproduce, test, and coordinate fixes, and what worked and what didn’t during a multi-issue security cleanup.

Jacob Rockowitz: Vibing Drupal: Using AI to hammer at the Webform module's security issues

Share this story

Send the public story page.

Useful takeaways from this story.

AI (Codex) accelerated reproducing hard-to-trigger bugs by generating regression tests and proofs-of-concept, even when it produced imperfect code.

A simple agent workflow and a dedicated "webform-security" skill helped organize and track 20+ security issues across multiple module branches.

Test-driven work—writing tests that reproduce issues first—made fixes verifiable and reduced regressions during a coordinated release.

# Summary Jacob Rockowitz describes a hands-on workflow for cleaning up 20+ security issues in Drupal's Webform module. He used Codex to help reproduce complex problems, generate regression tests, and assist with batching fixes across two supported branches. The approach combined test-driven fixes, a lightweight agent skill for tracking work, and human oversight to handle imperfect AI output and CI regressions.

# Why this mattered Webforms are public, accept user input, and therefore attract attacks that can expose data or allow XSS. The Webform module is older and widely extended, so even a stable codebase can accumulate security issues that are hard to reproduce and fix without clear tests and coordination.

# Practical workflow he used

  • Start with the oldest unresolved ticket and try to reproduce it. If reproduction is difficult, point Codex at the ticket to help write a regression test.
  • Use tests first: create a test that shows the issue. That both documents the bug and makes fixes verifiable.
  • Create a focused agent skill named "webform-security" that keeps a local list of markdown files to track each issue and its status.
  • For fixing across branches, ask Codex to apply each Merge Request (MR) to the main branch (6.3.x), cherry-pick into the older branch (6.2.x), and if a cherry-pick fails, generate a separate MR for that branch.
  • Automate staging: have AI produce a bash script to merge and stage many MRs into a private GitLab repository so Drupal.org CI can run all tests at once.

# What Codex did well and where it failed Codex excelled at organizing repetitive tasks, drafting regression tests, and coordinating MRs across branches. It could quickly produce tests that demonstrated how a specifically crafted URL or input bypassed SPAM protections. However, Codex sometimes generated sloppy code and struggled to correctly attribute authors in security advisories. When cherry-picks failed or regressions appeared, human intervention was required to resolve conflicts and refine fixes.

# Organizational lessons Keeping the process lightweight and incremental helped. Rockowitz intentionally avoided overengineering the agent skill: every time he worked on an issue, he had the agent create or update the skill so it would steer future work. The local markdown tracking and periodic creation of a meta ticket enabled a coordinated security release instead of ad hoc patches.

# Outcomes and recommendations

  • Create minimal, repeatable agent skills that automate bookkeeping and repetitive Git tasks, but expect to review and correct AI output.

# Bottom line Combining TDD, a small agent skill for tracking, and Codex's ability to automate repetitive tasks made an otherwise daunting security cleanup manageable. AI sped up reproduction and coordination, but the process relied on tests and human oversight to reach a reliable multi-issue release.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app