AI coding agents are now writing production code — which means security requirements need to be built into agent behavior from the start, not caught after the fact. This post breaks down what makes a security “skill” effective, where most fall short, and how to build ones that actually work.