Securing AI coding agents: preventing injection and leaks in internal codebases

West_umxwareness4908 · reddit · 2026-09-01

Discusses security controls for teams running AI coding agents against internal codebases. The focus is on the agent's potential actions rather than the model in isolation, highlighting risks such as malicious instructions in repositories, untrusted MCP server interactions, secret exposure, and dangerous operations. The author inquires about the use of policy enforcement, tool allowlists, sandboxed analysis, or approval workflows.

Original post →

More from coding & agent

coding & agent channel →