AI coding assistants speed up development, but generated code can contain vulnerabilities.
Common Issues
- Injection vulnerabilities in queries and commands.
- Missing input validation and output encoding.
- Hard-coded secrets and weak cryptography.
- Insecure defaults and outdated patterns from training data.
- Package hallucination: suggesting dependencies that don't exist — which attackers can then register with malicious code.
Why It Happens
Models learn from public code, which includes insecure examples, and they optimise for code that looks plausible and works, not necessarily code that's secure.
Controls
- Review: treat AI-generated code like any contribution — review it, especially security-sensitive parts.
- Automated scanning: static analysis, dependency scanning and secret detection in CI.
- Verify dependencies: confirm packages exist, are reputable and are the intended ones.
- Tests: including security tests for authentication, authorisation and input handling.
- Guidance: give assistants project security conventions in their instructions.
Agents With Commit Access
Coding agents that commit or deploy need permissions, sandboxing and review gates.
Use AI for Security Too
AI can also help review code for vulnerabilities — as an addition to, not a replacement for, established tools.