Writing / 2026

Your Coding Agent Inherits the Engineer

A coding agent inherits every credential the engineer holds and none of the judgment behind them. Close that gap with a runtime boundary, not a ban.

Your endpoint fleet is probably better governed than the panic headlines suggest: EDR watches processes, MDM enforces posture, DLP watches file movement. So state the problem precisely, because it isn’t that laptops are unwatched. It’s that on those watched laptops, a new kind of workload appeared, and no boundary was drawn around it. A coding agent runs as a child of the engineer’s shell, under the engineer’s UID, with the engineer’s SSH agent socket, cloud CLI session cache, kubeconfig, and every repository they’ve ever cloned. Call it the inherited-authority gap: the agent receives every credential the engineer accumulated, and none of the judgment that justified issuing them. Those credentials were granted to a person on the strength of their track record and their accountability. The process now wielding them is a loop that reads files, executes commands, and talks to the internet by design. Each verb is load-bearing for the product, and each is also the anatomy of exfiltration . Which of the two is happening at any moment is decided by configuration and prompt, not by anything your endpoint stack can see.

That’s the precise blind spot, and it’s worth naming for your security team in their own terms: existing telemetry has no causal attribution. EDR can log that git push ran and that bytes left for an API endpoint. It cannot say whether the human commanded that or the agent decided it, because both are the same UID running the same binaries in the same session. Every control you have distinguishes users and processes; none distinguishes intent within a session. July supplied the demonstration. A researcher put xAI’s Grok Build CLI behind a proxy and showed it uploading full Git bundles, every tracked file plus history, secrets in a tracked .env file included, to an xAI storage bucket, even with the “Improve the model” setting switched off; xAI disabled the upload by server-side flag within a day and Musk promised the data would be deleted, as The Register reported on July 14. Nothing on the endpoint distinguished that upload from a push the engineer meant. The vendor flipped a flag; the capability is the product, and the threat model follows from it, incident or no incident.

The fix is not a ban, which trades visibility for the feeling of control , and it is not asking each developer to set vendor ignore-lists, which are hints to a context engine, not access boundaries. The fix is the one security always reaches for when a workload’s authority must differ from its parent’s: a boundary the workload runs inside. Concretely, a sanctioned agent runtime, whether container, VM, network namespace, or remote workspace, whichever your platform team can operate, with four properties.

Mounts, not ignore-lists: the agent sees the project workspace it was invoked for, mounted in; the home directory, other repos, and anything a secret scanner flags are simply not present. Egress at the boundary: the runtime’s network path allows the agent vendor, your registries, and the project’s declared dependencies, and nothing else, enforced where causal process-tracking isn’t needed, because everything inside the boundary is by definition the agent. No inherited credential channels: this is the subtle one, because an unreadable private key is still usable through a forwarded ssh-agent socket. The agent doesn’t need to read the key to make it sign. Host credential sockets and session caches stay outside the runtime; what goes inside is a task-scoped identity issued per run, OIDC or cloud STS, short-lived, the same discipline as any other agent . And a joined audit trail: the runtime is the join key that endpoint telemetry lacked, so files read, commands run, and bytes out become one queryable record of what the agent, specifically, did.

Now the bill, because the objection that matters isn’t philosophical, it’s Tuesday morning: development destinations change constantly, and a strict boundary that blocks legitimate work gets overridden into decoration within a month. So roll it out like any control you want to survive contact. Observe-only first, measuring blocked-legitimate-action and override rates before enforcement. Tiered by risk, with repos holding production credentials or regulated data first and the hobby scripts last. And a published exception path with a latency target, so the boundary competes on convenience rather than authority.

The one-question audit that starts this program costs a day: how many agent processes ran on your endpoints last month, under which identities, reaching which destinations? If your tooling can’t answer, that’s the finding. The most capable new workload in your company is running inside your oldest assumption: that whatever the engineer’s session does, the engineer meant.