
The Agentic Coding Security Report
We had Claude, Codex, and Gemini build real applications and evaluated their results for security risks.
AI coding agents are quickly becoming part of modern development workflows. But what happens to application security when agents are writing the code?
To evaluate the risk, DryRun Security asked three leading coding agents, Claude, Codex, and Gemini, to build two real applications using a typical development workflow. Features were delivered through sequential pull requests, mirroring how real engineering teams ship code, and every change was analyzed by DryRun Security.
What we found:
To evaluate the risk, DryRun Security asked three leading coding agents, Claude, Codex, and Gemini, to build two real applications using a typical development workflow. Features were delivered through sequential pull requests, mirroring how real engineering teams ship code, and every change was analyzed by DryRun Security.
What we found:
87% of pull requests introduced at least one security vulnerability
143 security issues were identified across 38 scans
None of the agents produced a fully secure application
.webp)
Ready to build secure software, faster?
AI-native code security intelligence helps your teams detect vulnerabilities early, integrate security seamlessly into your CI/CD pipelines, and ship secure code with confidence.
.webp)
.webp)
.webp)
.webp)

.webp)


%20(1).jpg)
%20(1).png)