What is coding agent security?

By Identra · Updated

Coding agent security is the practice of controlling what AI coding agents can read, change, execute and send while completing development tasks. It protects source code, credentials and connected systems by limiting agent permissions, containing execution and reviewing consequential actions.

What does a coding agent attack look like?

Say a developer asks a coding agent to fix a failing build in a payments repo. A recent outside pull request added a troubleshooting doc. It tells the agent to upload its environment to a "diagnostics" URL first. The developer's shell has a deployment token exported.

If the agent follows the doc and nothing blocks the upload, a build fix just leaked a production credential. The code change itself can be perfect. Every test passes. Reviewing the diff would catch none of it.

Run the same task in a clean workspace with no deployment token and outbound traffic limited to the package registry. The upload fails and gets logged. Someone then reads the doc, works out where it came from and decides whether the token needs rotating anyway.

What can a coding agent reach?

Potentially whatever the developer can. Depending on its settings, Claude Code, Codex or Cursor running on your laptop can open a .env file, read ~/.aws/credentials, use your GitHub CLI session and call any MCP server you have configured. The task might be a one-line CSS fix. The reach can be your whole laptop.

Least privilege here means a scoped workspace and short-lived credentials for the task. Your everyday environment is the wrong default.

How do coding agents get redirected?

Agents read a lot of text nobody on your team wrote. READMEs, GitHub issues, code comments, dependency files, tool output. Any of it can carry instructions. When the agent treats that text as orders, you have indirect prompt injection.

The bait is usually mundane. "Print the environment to debug the auth failure." "Comment out the signature check so tests pass." Agents also make plain mistakes with no attacker involved, so the limits have to hold no matter why the agent wants to cross them.

Skills, plugins and MCP servers change what an agent can do mid-run. Review them like code. MCP security matters most when a connected server holds credentials or production data.

How do you set up a coding agent safely?

Keep a list of approved agents, extensions, skills and MCP servers, each with an owner and the repos it may touch. Approving Claude Code tells you nothing about how a given developer has configured it.

AI agent sandboxing does the heavy lifting. Anthropic's sandboxing guidance pairs filesystem limits with network limits, since either one alone leaves a path out. Check which processes the sandbox actually covers.

  • Give each task a workspace without unrelated repos, personal files or production data.
  • Strip secrets and signed-in sessions the task does not need.
  • Allow outbound traffic only to the services the task needs, such as your package registry.
  • Read install scripts before running them. A familiar package manager tells you nothing about the package.
  • Know what context goes to the model provider, including file contents and tool output.

Which coding agent actions should need approval?

"Run tests" sounds harmless. In most projects it executes whatever scripts the repo defines. Show the reviewer what will actually run.

Blanket approval for bash or python undoes every narrower rule. If a dedicated tool is blocked but the shell is open, the agent has a way around it. Human oversight works when the reviewer can see the consequence and reject that one operation.

  • Read and edit files in the task folder

    Control
    Keep it inside the workspace and review the diff
  • Run tests or install packages

    Control
    Isolated environment, scoped credentials, limited network
  • Touch another repo or a sensitive service

    Control
    Approve that resource and the minimum access
  • Publish, deploy or change access controls

    Control
    Go through the normal release or access process

What should you log and check?

Keep code scanning, dependency checks and human review. They judge the output. Agent controls govern the run. Changes to tests, CI config and security settings deserve extra scrutiny because an agent told to make tests pass has a reason to edit them.

An AI audit trail should link the developer, workspace, agent, tool calls, approvals and results. Mark what was proposed, attempted and completed. The logs will hold prompts and command output, so restrict them.

Try a harmless escape now and then. Ask the agent to read a marker file outside the workspace or reach a blocked test domain. Confirm it fails and shows up in the log.

How Identra thinks about it

Identra finds coding agents such as Claude Code and Codex on macOS and Windows devices, along with the MCP servers, skills and plugins they use. Prompts to Claude Code and Codex are checked on the device before they are sent, and blocked when policy is active. Agent tool calls are checked against policy, destructive shell commands are denied when policy is set to block, and every agent run is recorded with the user, device and outcome.

Go deeper: Identra on the endpoint

Frequently asked questions

How is this different from code scanning?

Code scanning checks the software. Coding agent security also covers what the agent does while writing it, like reading files, running commands and sending data out.

Can a coding agent read developer secrets?

Yes, if they sit in files, environment variables, sessions or connected tools it can reach. Keep them out of the agent's environment and scope the rest to the task.

Is a container enough?

It helps. Mounted home directories, passed-through credentials, privileged mode and open networking can undo it.

Does a local model remove the risk?

No. It changes where inference runs. The agent can still run bad commands or push data out through its tools.

Can a CLAUDE.md or AGENTS.md file enforce policy?

No. These files tell the agent what you expect. Enforcement belongs in the environment and the services it connects to.

Related terms

Keep exploring · AI apps, agents and usage