惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LINUX DO - 最新话题
Cyberwarzone
Cyberwarzone
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Security Archives - TechRepublic
Security Archives - TechRepublic
S
Securelist
V2EX - 技术
V2EX - 技术
www.infosecurity-magazine.com
www.infosecurity-magazine.com
P
Privacy & Cybersecurity Law Blog
Spread Privacy
Spread Privacy
N
News and Events Feed by Topic
H
Heimdal Security Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
大猫的无限游戏
大猫的无限游戏
L
LangChain Blog
爱范儿
爱范儿
阮一峰的网络日志
阮一峰的网络日志
G
GRAHAM CLULEY
L
Lohrmann on Cybersecurity
G
Google Developers Blog
Recorded Future
Recorded Future
H
Hacker News: Front Page
Application and Cybersecurity Blog
Application and Cybersecurity Blog
The GitHub Blog
The GitHub Blog
量子位
V
V2EX
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Vercel News
Vercel News
H
Help Net Security
Know Your Adversary
Know Your Adversary
Forbes - Security
Forbes - Security
T
Threatpost
S
SegmentFault 最新的问题
Hugging Face - Blog
Hugging Face - Blog
T
Threat Research - Cisco Blogs
人人都是产品经理
人人都是产品经理
Project Zero
Project Zero
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
罗磊的独立博客
C
Check Point Blog
P
Palo Alto Networks Blog
Google DeepMind News
Google DeepMind News
Last Week in AI
Last Week in AI
L
LINUX DO - 热门话题
Apple Machine Learning Research
Apple Machine Learning Research
C
Cybersecurity and Infrastructure Security Agency CISA
A
Arctic Wolf

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Snyk launches Evo ADS to secure AI coding agents with real-time governance
Dave Kurian · 2026-06-25 · via DEV Community

AI coding agents are no longer novelties—they now generate and ship production code, unsupervised, in enterprise environments. Security has not kept pace. Yesterday’s scanners watch code after it lands. AI agents, though, can call arbitrary tools, invoke “skills” from uncertain sources, and walk through internal APIs—all with no human watching. That’s the new perimeter—and Snyk Evo Agentic Development Security (Evo ADS) is the first tool designed to control it inside the agent’s workflow, live, before code or damage lands.

The headline: Evo ADS governs, not just after the fact, but as the agent runs. For the developer or security lead watching agents run inside the firewall, this is overdue and impressive.

What is Snyk Evo Agentic Development Security?

Evo ADS is a security governance layer for autonomous AI coding agents. Instead of passively scanning output, Evo ADS actively enforces rules around the tools, connections, and code actions that agents attempt during workflow execution. The focus isn’t just the code, but the entire perimeter: which MCP servers agents touch, the skills they install, and what outbound connections they make.

What sets Evo ADS apart from legacy security tools: placement in the loop. It integrates directly with the agent runtime. Before an agent can invoke an external tool or connect to an MCP server, Evo ADS intercepts and applies policy, preventing execution if a check fails. For AI coding workflows that use plugins, integrations, or operate via Model Context Protocol (MCP) servers, Evo ADS is the bouncer at the door, not the janitor after the party.

No code scanning product before Evo ADS has governed agent-initiated external actions and dynamic toolchains—legacy tools wait until after the code is written, missing the real risk surface. Evo ADS secures the actual, running behavior.

Why are autonomous AI coding agents a security challenge?

Autonomous agents don’t just write code. They operate—acting as developers or ops, calling shell tools, installing packages, and connecting via MCP servers to a web of skills and third-party APIs. A single agent may reach dozens of MCP-integrated tools in a shift. Security moves from static code analysis to active workflow governance.

Snyk’s telemetry makes clear the scale and risk:

  • In a sample of 9,700 developer environments, 43% ran two or more AI coding platforms simultaneously.
  • More than half had at least one MCP server active; the most heavily instrumented cases ran over 80.
  • One in 12 environments with MCP saw high or critical security findings.

This isn’t a subtle finding. It’s structural. Legacy scanners have zero view into which tools the agent is connecting to, who supplied a given “skill,” or how data flows across MCP boundaries. Attackers have noticed.

MCP servers, by design, turn code completion tools into fully programmable orchestration agents. But without governance, they are a shadow supply chain. Skills can reference arbitrary dependencies or fetch code from external instructions, often invisible to the primary dev team. Snyk’s enterprise design partner review surfaced an average of 18 agent skills per developer, with 1/10th referencing outside dependencies. For security, the attack surface is sprawling and dynamic.

How does Evo ADS protect AI coding workflows?

Evo ADS operates at three pivotal layers, each mapped tightly to AI agent pain points. This is not post-hoc scanning. Enforcement happens in the workflow.

Stage 1: Pre-execution vetting
Before an agent uses anything—MCP server, plugin, tool, or skill—Evo ADS demands an inventory and applies trust policies:

# Register allowed MCP servers and skills
snyk agent-inventory add --mcp myserver.local --skill fetch-customer-data
# Validate external dependency provenance before allowing install
snyk skill-audit check fetch-customer-data

Attempts to use unvetted components are blocked. You do not need to wait for the exploit to learn about it.

Stage 2: Real-time policy enforcement on agent actions
As the agent runs, Evo ADS injects runtime policy hooks. If an agent attempts to call an unapproved endpoint, install a package from an untrusted registry, or access external resources, Evo ADS enforces controls immediately:

# Example: runtime policy configuration
policies:
  - action: block
    when:
      - from: ai_agent
        tries: mcp_connect
        to: unapproved_server
      - from: ai_agent
        tries: skill_install
        package_source: unverified_registry

This is not best-effort auditing—it is hard-stop enforcement. Developers and operators get alerts in real time, not hours later.

Stage 3: Real-time scan and fix of AI-generated code
Finally, as the agent emits new code, Evo ADS triggers live vulnerability scanning and can auto-apply select patches:

# Scan new files as generated (live in agent workflow)
snyk code-scan --watch path/to/generated/
# Optional: enable fix mode for auto-remediation
snyk code-fix --apply

The engine catches CVEs, risky patterns, and known vulnerable code before it ships. Not “after the merge”—literally as the code lands in the folder.

Key advantage: putting controls in the loop, not after. Attack surface never widens past the agent boundary. Compliance, incident response, and real-time rollback become tractable.

[[DIAGRAM: agent workflow with Evo ADS at entry (tool/skill vetting), runtime (action enforcement), and exit (code scan/fix) points]]

How can developers use Snyk Evo ADS today?

Getting Evo ADS into your workflow is procedural and can be staged.

1. Setup and integration
You need access to your AI coding agent platform (Open Interpreter, custom agent, etc.), MCP server endpoints, and developer environment inventory. Evo ADS multiplatform installers or Docker images are geared for both local and CI/CD integration:

# Install Evo ADS for agent governance
npm install -g snyk-evo-agent
# Or as a CI/CD pipeline step
docker pull snyk/evo-agent:latest

For cloud agent platforms:

# Example pipeline step in GitHub Actions
- name: Evo ADS Preflight
  run: snyk agent-inventory sync --output-report

2. Registering and managing agent assets
Agents, MCP servers, and skills inventories live in Evo ADS’s policy engine. Continuous inventory means every running agent, plugin, and third-party “skill” is accounted for:

# Inventory collection and review
snyk agent-inventory list
# Bulk import from fleet
snyk agent-inventory import path/to/agent-configs/

Security teams can finally answer, “What’s running?” for the first time.

3. Monitoring and incident response
Evo ADS streams findings and policy events to your SIEM or Snyk console:

# Export telemetry to SIEM for detection/alerting
snyk agent-telemetry export --to splunk

If a policy violation or vulnerable code emission occurs, Evo ADS can trigger automated incident workflows—block, alert, roll back. Teams gain real-time visibility and fine-grained control.

With this model, adoption is not “rip and replace.” Evo ADS can wrap existing agent deployments or sit alongside legacy scanning, providing real-time coverage for areas older tools ignore.

What impact does Evo ADS have on enterprise software security?

Evo ADS closes a foundational gap: live, inside-the-tailpipe enforcement for AI agent workflows. Enterprise numbers make the case:

  • In Snyk’s telemetry, one in 12 MCP environments had high or critical security findings. Those can now be blocked before code or data is ever touched.
  • Skill sprawl: Organizations average 18 installed agent skills per developer. Evo ADS turns that inventory into a governable perimeter—third-party and shadow skills are no longer invisible risks.
  • Unauthorized actions—calling outbound APIs, installing unauthorized tools, fetching external code—are now blockable in the loop, rather than detected hours or days later.

Early adopters and enterprise design partners now see agent, MCP, and skill inventories for the first time—an end to the shadow infra. Security teams gain a direct way to manage, sanction, or restrict AI agent behaviors with one policy engine. The result: measurable drops in agent-originated vulnerability surface, faster containment, and a meaningful shift from forensics to prevention.

What this gets us

If you deploy AI coding agents or run MCP servers, Evo ADS gives you a perimeter that moves with the agent—not waiting for a post-mortem, but blocking malicious calls at the edge of action. You inventory your agents, govern the skills and servers they touch, and catch vulnerabilities—before they trigger harm. Teams already running multiple AI systems simultaneously now have the real-time enforcement they need to stop incidents early instead of cleaning up after the fact.

OTF’s layer makes policy and configuration portable as tools and AI agents churn; the security boundary holds, even as underlying models and agent platforms change.

Evo Agentic Development Security isn’t just a new scanner. It’s the real-time firewall for AI-powered code. That’s overdue—and now possible.