Secure Agentic Software Development: Beyond Vibe Coding
Secure Agentic Software Development: Beyond Vibe Coding
MP4 | Video: h264, 1920×1080 | Audio: AAC, 44.1 KHz, 2 Ch

What the evidence actually says

DORA 2025: AI is an amplifier – it raises throughput and instability together.
Veracode: across 80 tasks, models chose the insecure implementation about 45% of the time.
METR: experienced developers measured 19% slower with AI while estimating they were 20% faster.
GitGuardian: AI-assisted commits leak secrets at roughly twice the human rate.

The six controls you will build

Specify – agent-executable specs with machine-checkable acceptance criteria, non-goals and stop conditions.
Constrain – least-agency permission tiers, sandboxing, worktrees and default-deny egress.
Review – a checklist tuned to what agents actually get wrong, a ten-minute triage, and adversarial agent-vs-agent review.
Test – tests as a contract the agent cannot game, plus mutation testing to prove the suite has teeth.
Gate – seven blocking CI checks: secrets, static analysis, dependencies, tests, test integrity, SBOM and a workflow audit.
Prove – commit provenance, SBOM and signed attestations that answer an auditor without a human explaining.

Built around one company, one incident

Everything is taught through Meridian Ledger, a Series-B fintech that went agent-first and lost six hours of reconciliation when an agent deleted a runtime-injected credential during a release freeze. Every control in the course answers a specific thing that went wrong that Thursday.

Hands-on and tool-agnostic

Eight labs, six assignments and three role plays, all built on open-source tooling – Semgrep, gitleaks, OSV-Scanner, Syft, Grype, promptfoo, mutmut and zizmor. No lab requires a specific vendor’s coding agent, because your control plane has to outlive your tool choices. You will break a repo on purpose, review a pull request with seven planted defects, catch a reward-hacked test suite, and wire a CI gate that blocks all of it.

Who this is for

Senior and staff engineers whose teams already merge agent-authored pull requests; application-security and platform engineers asked to make the AI rollout safe; and engineering leaders accountable for both the velocity number and the incident.