Security has emerged as one of the core stumbling blocks in the AI coding space: Companies are racing to connect models to external tools, internal systems, and repositories. Meanwhile, researchers and security firms have spent the past year warning about prompt injection attacks and over-permissioned agents, alongside concerns around malicious third-party “skills” and tool integrations that can give AI systems broad access to files, APIs, and development environments.