
Findings and evidence
Mandiant examines architectural risks introduced when AI agents enter development and vulnerability-management workflows. Its guidance focuses on deterministic controls, careful integration and human judgment around privileged automation.
Why it matters
For a review of your own code, document the permitted data and actions, keep credentials narrowly scoped and retain an audit trail of proposed changes. The approval boundary should be enforced by the application, not only by a prompt.
Scope and limits
This is consulting guidance supported by scenarios, not a controlled benchmark proving one universal architecture. Suitability depends on the environment and the agent’s actual privileges.
Primary source
Google / Mandiant: original publication. Source published 2026-07-16. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.