Security and Governance for AI Coding Agents
Ongoing security incidents (Claude Code slowdown ignore, Azure DevOps MCP flaw, FakeGit, Tego symlink, Sygnia pen test, Silverfort OAuth token vuln, Mitiga's CLAUDE.md threat intel). New frameworks (7 reusable artifacts, five-layer attack surface model), sandboxing solutions (Upstash Box SDK), and enterprise guardrails (Legit Security VibeGuard 2.0, OX Security MCP integration). Didit identity verification MCP server evaluation adds to security reference material.
Sources (2)
Updated Aug 5, 2026