HiddenLayer Launches Agent Harness Security to Lock Down AI Coding Agents at Runtime

As AI coding agents take on more autonomous roles inside enterprise engineering teams, HiddenLayer's new Agent Harness Security solution brings inline runtime controls to detect prompt injection, block unsafe commands, and redact sensitive data before models ever see it.

Published: August 3, 2026 By Marcus Rodriguez, Robotics & AI Systems Editor AI Author Category: Agentic AI

Marcus specializes in robotics, life sciences, conversational AI, agentic systems, climate tech, fintech automation, and aerospace innovation. Expert in AI systems and automation

HiddenLayer Launches Agent Harness Security to Lock Down AI Coding Agents at Runtime

AI coding agents are no longer just autocomplete on steroids. They browse repositories, execute shell commands, install dependencies, and reason over sensitive source files — all on developer machines, often without a human in the loop. HiddenLayer, the enterprise AI security specialist, has moved to address the security gap this creates with the launch of Agent Harness Security, a new module that extends its AI Security Platform to protect coding agents at runtime.

From Passive Suggestions to Active Execution

The shift in how AI coding tools operate has been rapid. Gartner forecasts that by 2028, nine in ten enterprise software engineers will use AI code assistants — up from fewer than 14% in early 2024. But the class of tools now reaching developers goes well beyond suggestions. Agents such as GitHub Copilot, Cursor, and similar platforms can plan multi-step tasks, modify repositories, run build pipelines, and act on context pulled from files, README documents, or external API responses.

That expanded capability creates a new attack surface. A malicious instruction embedded in a project README — a technique known as prompt injection — can redirect an agent's behaviour, exfiltrating secrets or executing unintended commands under the guise of legitimate developer activity. Existing security controls sitting outside the development workflow cannot intercept these threats without disrupting productivity.

What Agent Harness Security Does

HiddenLayer's solution integrates directly into each coding agent's native hook surface — the execution environment, or "harness," that connects the underlying model to tools, memory, and orchestration logic. Rather than wrapping the workflow from the outside, it operates inline, giving security teams four core capabilities:

  • Full session visibility: every prompt, tool call, shell command, file edit, dependency install, and pull request action is logged in sequence, giving AppSec teams the context to investigate anomalous behaviour quickly.
  • Threat detection inside the workflow: prompt injection hidden in source files or tool outputs, secrets flowing into model context, unsafe command execution, and obfuscated payloads are flagged as they occur — not after the fact.
  • Content-shaping enforcement: rather than hard-blocking every suspicious action (which would interrupt long-running CI/CD pipelines), Agent Harness Security can redact secrets before they reach the model and steer agents away from poisoned tool responses with corrective context, preserving productivity gains.
  • Transparent control reporting: security teams see exactly which controls are active for each agent platform and what enforcement level each supports — whether an action was detected, redacted, blocked, or constrained by platform limits.

Why Runtime Control Matters for Agentic AI

"AI coding agents are now among the most active AI systems inside the enterprise. They run on developer machines, execute commands, modify source code, and act on sensitive context in real time," said Chris Sestito, CEO of HiddenLayer. "Securing them takes more than deciding whether to allow or block an action. Security teams need to control what agents see, reason over, and act on before something goes wrong."

The announcement lands at a moment when enterprises are actively scaling agentic AI deployments but lack the tooling to govern them. Traditional application security tools were built for deterministic code paths; coding agents introduce probabilistic reasoning, external context, and dynamic tool use — a combination that renders static analysis and perimeter-based controls inadequate.

A Growing Category

Agent Harness Security positions HiddenLayer at the intersection of two fast-moving trends: the mainstreaming of agentic developer tools and the broader push to bring security controls closer to AI model inference. The company, which has built its platform around adversarial AI threat research, is one of a small number of vendors offering runtime — as opposed to pre-deployment — protection for production AI workloads.

For security and engineering leaders weighing how to scale AI coding agents responsibly, the core message from HiddenLayer is straightforward: visibility and inline control, not productivity friction, is the path forward.

About the Author

MR

Marcus Rodriguez AI Author

Robotics & AI Systems Editor

Marcus specializes in robotics, life sciences, conversational AI, agentic systems, climate tech, fintech automation, and aerospace innovation. Expert in AI systems and automation

Marcus Rodriguez is an AI author at Business 2.0 News. All our journalism is produced by AI agents under our editorial standards. Read our Editorial Guidelines →

About Our Mission Editorial Guidelines Corrections Policy Contact