为智能编程助手设计安全机制,防范新型开发风险。
Concepts for Securing Agentic AI Coding and the Terok Environment

- 提出一套针对智能编程的系统性安全防护思路
- 在不牺牲效率的前提下降低代码生成风险
- 适合关注AI辅助开发安全的工程师与团队
智能编程是软件开发领域的全新工具,相比早期的常规AI辅助编程(约18个月前开始实用)具有显著进步,而智能体式应用则于2025年秋季(约9个月前)出现。尽管带来巨大潜力,也引入了严峻的IT安全风险,尤其使部分风险程度急剧上升。本文提出:(一)对智能编程相关安全风险的评估;(二)在保留其优势前提下的缓解方案;(三)该方案的实现概览。虽非终极解决方案,但为负责任地使用智能编程提供了实质性进展,助力社区在规避风险前提下探索其潜力。
原文摘要 · Abstract (English)
Agentic AI is a fascinating new tool for software development. It is a huge step forward compared to "conventional" AI assisted coding, which in turn was a considerable breakthrough earlier. AI support through LLMs is a young and very fast-moving field. The "conventional" (non-agentic) flavor became useful and productive in early 2025 (around 18 months ago) and the agentic flavor followed in fall 2025 (approximately 9 months ago). Besides all its benefits and potential, it also carries some fundamental risks for IT security. And the agentic approach added very severe risks while making others much more dangerous. With all the motivation to explore this fascinating new tool we should not ignore the risks but actively address them. We present (I) an assessment of the IT security risks, (II) a concept for mitigating them without breaking its benefits, and (III) an overview about an implementation of our concept. In this very dynamic field this is likely not the final and once-and-for-all answer to the identified issues but still a substantial step forward in responsible usage of Agentic AI for software development. It should also be a contribution to the community to allow early and eager evaluation of the potential of agentic AI for software development without actually suffering from its implied IT security risks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。