Solutions

Enable AI-driven development safely

Your security policy applied to agent-written code, from the first prompt to production.

One agent change, every checkpointacme/orders
The challenge

Agents write more of the code. Security checks it once, at the pull request.

AI-generated code
45%

of AI-generated code samples failed security tests.

In the agent

The agent checks its own work.

Agent Skills and the MCP server put Heeler checks inside the coding agent.

Packages checked before install
Staged changes scanned for secrets
Open findings for the file it edits
Claude Code · acme/ordersAgent session
Add Stripe checkout to the orders service
heeler skill · recommended version
stripe 8.2.02 advisories14.21.0safest version
heeler skill · secrets scan, staged changes
STRIPE_SECRET_KEY · config/dev.env:4moved to an environment variable
heeler MCP · SAST results for the file
orders/checkout.py0 open findings
Committed clean
Commit and CI

Every commit and pipeline, checked.

The CLI runs the same checks in pre-commit hooks and in CI.

Secrets blocked at commit
Vulnerabilities, licenses and package age
Malicious packages and risky agent files
CI · heelercli ci1 check failed
VulnerabilitiesPass
Dependency policylicense, minimum package age
Pass
Malicious packagesPass
SecretsPass
Agent filescurl | bash in .claude/hooks/setup.sh
Fail
Pull request

Pull requests held to your policy.

PR Guardrails block or flag changes by service tier and exposure.

Observe, Warn or Block per rule
Scoped by tier and internet exposure
New skills and MCP configs flagged
PR #1182 · Add Stripe checkoutTier 1Internet accessible
RuleModeResult
Active ExploitBlockPassed
Secret ScanningBlockPassed
Compromised DependencyBlockPassed
New SAST findingshigh severity
WarnPassed
Agent File Change.mcp.json · new server stripe-admin
WarnFlagged
Passed with 1 warning
After release

What gets through gets fixed.

Autotriage ranks each finding by real exposure. Auto-fix opens the fix.

Ranked by reachability and exposure
Fix PRs validated in your CI
Tracked to your SLOs
Evidence

Every decision on record.

Findings, guardrails and policy changes map to the standards you report on.

OWASP ASVS 5.0.0, EU CRA and DORA
Policy changes logged with user and time
Point-in-time reports, PDF or CSV
Standards report · October 2026PDF · CSV
OWASP ASVS 5.0.0
EU Cyber Resilience Act
DORA
Verified by Heeler
Needs attestation
Audit Log
Oct 2a.patelAgent File Change: Warn → Block
Oct 1j.ruizTrusted domain added: pkg.acme.dev
Sep 29a.patelGuardrail scope: Tier 1 and Tier 2