Agentic Development Security: How to Secure Code Your Agents Write
Blog post from Endor Labs
Agentic development security addresses risks arising when AI coding agents autonomously generate, select, and merge code, dependencies, and tool integrations, requiring continuous controls that operate at machine speed rather than relying solely on human review. It differs from agentic AI security by focusing on the software build process rather than protecting AI-agent applications in production. Key risks include insecure generated code, hallucinated dependencies that attackers can exploit through slopsquatting, insecure or untrusted Model Context Protocol servers, and prompt injection combined with overly broad agent permissions. Recommended practices include treating all agent outputs as untrusted, validating packages before installation, applying least-privilege access and approval requirements for high-impact actions, maintaining tool inventories, and aligning controls with OWASP and NIST frameworks. The discussion emphasizes reachability-based analysis to prioritize vulnerabilities that can actually be executed in deployed applications, reducing alert noise and helping teams preserve development speed; it also presents Endor Labs products and reported performance outcomes as an example of this approach.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 9 | 2,241 | 148 | 72 | -74% |
| LLM | 7 | 747 | 162 | 79 | -85% |
| AI Agents | 6 | 931 | 231 | 103 | -84% |
| AI Coding Assistant | 4 | 341 | 115 | 55 | -77% |
| Real-time | 1 | 649 | 155 | 80 | -85% |
| Secrets Management | 1 | 451 | 99 | 43 | -80% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.