Ah, damn. Bitwarden has Agents.md. That doesn't really fill me with confidence, and it's the most critical software I use.
I need to update my threat model, I've trusted them quite a lot to the point of using Bitwarden for MFA for less-important services (so it's not really MFA, since both my password and MFA token is in Bitwarden, but it's super convenient), and only had Yubikey for my Bitwarden account, so as long as the app itself isn't compromised I should be good (and Bitwarden has a pretty good track record as far as I know), but if they are going to start vibe-coding their tools then it's probably time to move to a proper MFA.