Skip to content

security

1 post with the tag “security”

Building a Security Auditor Into a Coding Agent

Building a security auditor into a coding agent: a read-only sub-agent runs SAST, secret, and dependency scans and reports CWE/OWASP findings, built on the principle that a scan that did not run must never read as clean.

An AI agent that writes code should be able to check it, too. But a security tool has a failure mode no other tool has: a false ‘clean’ is worse than no tool at all, because it manufactures unearned confidence. Here is how we built a read-only security auditor into CodeBuddy around that single idea.