Distributing Security Controls Through Harness Engineering· 通过 Harness 工程分发安全控制
AI coding agents are being adopted at historic speed, yet security and risk concerns remain the primary barrier to scaling agentic AI across organizations. Existing security controls for coding agents are not systematically distributed to engineering teams, and vendor-native solutions introduce ecosystem dependencies that may not suit every deployment context. This paper investigates whether off-the-shelf security controls can be implemented on commercial AI coding agents and scaled to a distributed user base via a custom agent harness. A phased testing methodology was applied across four agent configurations --- two commercial agents with and without controls, a baseline harness, and a security-hardened harness --- using a 23-test suite derived from the OWASP Top 10 for Agentic Applicatio
研究通过定制 Harness 架构在商业 AI 编码代理中系统性实施和扩展安全控制
- 核心方法
- 采用分阶段测试方法,在四种代理配置上实施基于 OWASP Top 10 的 23 项测试套件
- 适合谁读
- 适合研究者、工程师和安全专家阅读
- 要解决的问题
- 现有的 AI 编码代理安全控制不均匀,且厂商原生解决方案可能不适合所有部署环境
- 关键实验
- 使用 23 项测试套件对四种代理配置进行了详细实验
- 主要贡献
- 提出并验证了一种安全增强型 Harness 架构,能够有效扩展安全控制至分布式用户群体
- 意义与局限
- 为组织内大规模部署 AI 编码代理提供了可行的安全解决方案,但有效性依赖于具体部署环境