Solutions
Enable AI-driven development safely
Your security policy applied to agent-written code, from the first prompt to production.
One agent change, every checkpointacme/orders
In the agentstripe 8.2.0 swapped for 14.21.0
CheckedAt commitAWS key in deploy/env.sh
BlockedIn CI5 checks
PassedPull requestAgent File Change · .mcp.json
WarnedAfter releaseNew CVE in urllib3 · fix PR #1204
FixedPR #1182 merged with your policy applied at every step
The challenge
Agents write more of the code. Security checks it once, at the pull request.
AI-generated code
45%
of AI-generated code samples failed security tests.
Where an agent change gets a security check today
- Prompts and tool calls
- Packages the agent installs
- The commit
- The pull request
- After release
In the agent
The agent checks its own work.
Agent Skills and the MCP server put Heeler checks inside the coding agent.
Packages checked before install
Staged changes scanned for secrets
Open findings for the file it edits
Claude Code · acme/ordersAgent session
Add Stripe checkout to the orders service
heeler skill · recommended version
stripe 8.2.02 advisories14.21.0safest version
heeler skill · secrets scan, staged changes
STRIPE_SECRET_KEY · config/dev.env:4moved to an environment variable
heeler MCP · SAST results for the file
orders/checkout.py0 open findings
Committed clean
Commit and CI
Every commit and pipeline, checked.
The CLI runs the same checks in pre-commit hooks and in CI.
Secrets blocked at commit
Vulnerabilities, licenses and package age
Malicious packages and risky agent files
$ git commit -m "Add deploy script"
heelercli secrets --pre-commit
✕ AWS access key · deploy/env.sh:12
commit blocked
CI · heelercli ci1 check failed
VulnerabilitiesPass
Dependency policylicense, minimum package age
PassMalicious packagesPass
SecretsPass
Agent filescurl | bash in .claude/hooks/setup.sh
FailPull request
Pull requests held to your policy.
PR Guardrails block or flag changes by service tier and exposure.
Observe, Warn or Block per rule
Scoped by tier and internet exposure
New skills and MCP configs flagged
PR #1182 · Add Stripe checkoutTier 1Internet accessible
RuleModeResult
Active ExploitBlockPassed
Secret ScanningBlockPassed
Compromised DependencyBlockPassed
New SAST findingshigh severity
WarnPassedAgent File Change.mcp.json · new server stripe-admin
WarnFlaggedPassed with 1 warning
After release
What gets through gets fixed.
Autotriage ranks each finding by real exposure. Auto-fix opens the fix.
Ranked by reachability and exposure
Fix PRs validated in your CI
Tracked to your SLOs
New findingurllib3 2.0.6CVE published after release
AutotriageUrgent
Function reachableInternet accessibleTier 1
Auto-fixPR #1204 · 2.2.3CI green · merge-ready
Evidence
Every decision on record.
Findings, guardrails and policy changes map to the standards you report on.
OWASP ASVS 5.0.0, EU CRA and DORA
Policy changes logged with user and time
Point-in-time reports, PDF or CSV
Standards report · October 2026PDF · CSV
OWASP ASVS 5.0.0
EU Cyber Resilience Act
DORA
Verified by Heeler
Needs attestation
Audit Log
Oct 2a.patelAgent File Change: Warn → Block
Oct 1j.ruizTrusted domain added: pkg.acme.dev
Sep 29a.patelGuardrail scope: Tier 1 and Tier 2
