DeepKeep AI Lens adds guardrails for AI coding agents

DeepKeep AI Lens adds guardrails for AI coding agents

DeepKeep has launched AI Lens for Developers, an extension to its AI usage control and runtime protection modules. It is built to give security teams oversight of coding agents that write, change and run code for developers.

The company says the tool brings policy enforcement, audit visibility and runtime security to agents such as Cursor and Claude Code. According to DeepKeep, this covers ground that most security programs have not had to deal with before.

Why coding agents are a problem

DeepKeep's announcement says 90% of developers use AI coding agents at work at least once a week. These agents run on the developer's endpoint. They can read local files, execute shell commands and call MCP (Model Context Protocol) tools directly on the machine.

The company argues that security teams currently cannot see what these agents do with that access, and have no way to stop them. Agents now play a bigger part in the software development life cycle (SDLC), so code can travel from a prompt to production with much less human review along the way.

Mistakes in this space are already visible. Earlier this week, researchers described how AI agents leaked screenshots to GitHub, a reminder that agent output can end up in public places with little oversight.

How AI Lens works

DeepKeep describes AI Lens as a light plug-in rather than a full endpoint agent. It watches agent activity both before and after each action runs. The company says this gives security teams coverage without installing another endpoint client on developer machines.

Hooks inside the coding agent intercept prompts, shell commands, file reads and MCP tool calls. Each one is sent to DeepKeep's system, which decides whether to allow it, block it or log it for audit.

The tool looks for several kinds of risk:

  • credentials, tokens and passwords that could leak through prompts or attached files
  • insecure code patterns in agent output, such as a function that lacks authentication
  • destructive commands, which are held and sent to a human for approval before they run
  • custom key phrases, which teams can set to flag sensitive code sections or internal repositories by name

The credential checks address a familiar weakness. Secrets slipping into code and prompts remain common, as shown by recent findings that GitHub repositories expose valid credentials at large scale.

Audit logs and central policy

Every session generates a full audit log. It records the device ID, the prompt content and the user ID. DeepKeep says this means security teams keep a record of events even when a developer edits a blocked request and submits it again.

Policies are managed through a Policy Hub. Administrators can write rules for specific roles or for the whole organization. Categories that can be blocked include personally identifiable information (PII), credentials and destructive commands.

"Not just whether they're approved on paper"

Ofer Rotberg, VP Product at DeepKeep, pointed to the level of access developers hold.

"Developers have more permissions and access than almost anyone else in the organization, and coding agents now act with full autonomy and responsibility. The risk is real, as the recent OpenAI and Hugging Face incident showed, where AI agents were able to access and exploit external systems during testing," he said.

"It is essential for CISOs to maintain visibility into what's happening inside these tools, not just whether they're approved on paper. Security teams must monitor every agent action and block harmful behaviour in real time, instead of sitting and waiting for the next incident."

Availability

AI Lens for Developers currently supports Cursor and Claude Code. DeepKeep says support for GitHub Copilot, OpenAI Codex, Lovable, Windsurf and other tools is coming soon. The extension is available now as part of DeepKeep's broader AI security platform.

Our Take

The launch reflects a shift in where AI risk sits. Much of the early focus was on chatbots and what employees paste into them. Coding agents are a different case because they act. They read files, run commands and call tools on machines that often hold the keys to source code and production systems.

DeepKeep's approach of hooking each action and routing destructive commands to a human addresses that directly. It is worth noting the persistent audit trail, which could matter for incident response if an agent does something unexpected. Recent cases such as the DIVD breach by an autonomous AI agent suggest that agent behaviour is becoming a real investigation topic.

Open questions remain. Approval prompts only help if developers do not click through them out of habit. It is also worth watching how quickly DeepKeep delivers the promised support for Copilot, Codex and others, and whether coding agent vendors build similar controls into their own products.