DeepKeep 宣布推出面向开发者的 AI Lens,这是该公司 AI 使用控制和运行时保护模块的新增扩展功能,旨在保护软件开发者及其代表其编写、修改和执行代码的编码代理。
该功能为安全团队提供了策略执行、审计可见性以及针对 Cursor 和 Claude Code 等编码代理的运行时安全保障,填补了以往大多数安全项目未能覆盖的关键空白。
90% 的开发者每周至少在工作时使用一次 AI 编码代理,这造成了日益严重的安全问题。这些端点代理可以读取本地文件、运行 Shell 命令,并直接调用该开发者机器上的 MCP 工具。安全团队无法得知这些代理利用这些权限正在做什么,更不用说阻止它们了。随着代理在软件开发生命周期(SDLC)中角色的增加,代码从提示词到生产环境的流转过程中,每一步的人工审查都大幅减少。
DeepKeep 的 AI Lens for Developers 部署了针对开发者实际工作方式的护栏和全天候监控,跟踪并过滤开发者和其代理的行为。AI Lens 作为轻量级插件而非完整的端点代理构建,能够在代理运行前后捕获其活动,使安全团队能够在不增加开发者机器上新端点客户端负担的情况下获得覆盖。
AI Lens 会标记可能通过提示词和附加文件泄露的凭据、令牌和密码,并捕获代理生成的不安全代码模式,例如缺少身份验证的函数。破坏性命令会被标记并在运行前发送给人工审批,团队还可以设置自定义关键词检测,以按名称标记敏感代码部分或内部仓库。
每个会话都会生成完整的审计日志,包括设备 ID、提示词内容和用户 ID,因此即使开发者调整了被阻止的请求并再次尝试,安全团队也能拥有发生情况的记录。管理员通过策略中心(Policy Hub)设置策略,按角色或跨组织配置规则,以阻止个人身份信息(PII)、凭据或破坏性命令等类别。
内置于编码代理中的钩子会在提示词、Shell 命令、文件读取和 MCP 工具调用运行前后拦截这些操作,并将每一个路由到 DeepKeep 的系统进行允许、阻止或审计决策。
DeepKeep 产品副总裁 Ofer Rotberg 表示:“开发者的权限和访问权限比组织中几乎任何人都多,而编码代理现在以完全的自主权和责任行事。风险是真实存在的,最近的 OpenAI 和 Hugging Face 事件表明,AI 代理能够在测试期间访问并利用外部系统。”
“对于首席信息安全官(CISO)来说,保持对这些工具内部发生情况的可见性至关重要,而不仅仅是它们是否在纸面上获得批准。安全团队必须监控每一个代理操作并实时阻止有害行为,而不是坐等下一次事故发生。”
AI Lens for Developers 目前支持 Cursor 和 Claude Code,GitHub Copilot、OpenAI Codex、Lovable、Windsurf 等也将陆续推出。它现已作为 DeepKeep 更广泛的专用 AI 安全平台的一部分提供。
DeepKeep has announced AI Lens for Developers, a new extension to the company’s AI usage control and runtime protection modules to secure software developers and their coding agents that can write, modify, and execute code on their behalf.
The capability gives security teams policy enforcement, audit visibility, and runtime security over coding agents such as Cursor and Claude Code, closing a critical gap most security programs have ever had to cover before.
90% of developers use AI coding agents at work at least weekly, creating a growing security problem. These endpoint agents can read local files, run shell commands, and call MCP tools directly on that developer’s machine. Security teams have no way to see what these agents are doing with that access, let alone stop it. This shift, with its increased role for agents in the software development life cycle (SDLC), has code moving from prompt to production with far less human review at each step.
DeepKeep’s AI Lens for Developers deploys guardrails and full-time monitoring that target how developers actually work, tracking and filtering what developers and their agents are doing. Built as a light plug-in rather than a full endpoint agent, AI Lens catches agent activity before and after it runs, allowing security teams to get coverage without adding a new endpoint client footprint to developer machines.
AI Lens flags credentials, tokens, and passwords that can leak through prompts and attached files, and catches insecure code patterns in what an agent generates, such as a function missing authentication. Destructive commands are flagged and sent for human approval before they run, and teams can set custom key-phrase detection to flag sensitive code sections or internal repositories by name.
Every session produces a full audit log, including device ID, prompt content, and user ID, so security teams have a record of what happened even after a developer adjusts a blocked request and tries again. Administrators set policy through a Policy Hub, configuring rules by role or across the organization to block categories like personally identifiable information (PII), credentials, or destructive commands.
Hooks built into the coding agent intercept prompts, shell commands, file reads, and MCP tool calls before and after they run, and route each one to DeepKeep’s system for an allow, block, or audit decision.
“Developers have more permissions and access than almost anyone else in the organization, and coding agents now act with full autonomy and responsibility. The risk is real, as the recent OpenAI and Hugging Face incident showed, where AI agents were able to access and exploit external systems during testing,” said Ofer Rotberg , VP Product of DeepKeep.
“It is essential for CISOs to maintain visibility into what’s happening inside these tools, not just whether they’re approved on paper. Security teams must monitor every agent action and block harmful behaviour in real time, instead of sitting and waiting for the next incident.”
AI Lens for Developers supports Cursor and Claude Code today, with GitHub Copilot, OpenAI Codex, Lovable, Windsurf, and more coming soon. It is available now as part of DeepKeep’s wider, dedicated AI security platform.
首次收录 · 2026-10-02 · 7.54 分