We analyzed the security of AI coding agents. The result: broken auth, SSRF, and missing defenses.
Tenzai researchers tested Cursor, Claude Code, Codex, Replit, and Devin. Every AI coding agent shipped vulnerable code. Here’s what broke - and why it matters.
blog.tenzai.com