A lot of security and safety is about processes, checks, clear people in charge of clear things, and clear access limits. That goes out the window with these “agents. It becomes harder to identify where things went wrong, or what types of tests you need to do to check for vulnerabilities and who is in charge of which issue.

Some experienced software engineers talked about how it's easy to just press “accept” of the buggy code that you see generated by Claude. So the question is, what about the new vulnerabilities created by using these “agents”? We’ve seen so many examples of issues, like people wiping out their entire production data.

Impulsos
Me recuerda a la urgencia por sacar producto: en una cooperativa pequeña de software libre, la tentación de aceptar lo que genera el asistente es fuerte, pero el coste lo pagas luego. Nosotras hemos empezado a tratar esas sugerencias como código de terceros: revisión, pruebas y documentación antes de tocar producción. Así no renuncias a la herramienta, pero la integras con criterio comunitario.