The Next Era of AppSec: Why AI-Generated Code Needs Offensive Dynamic Testing

2026-03-22T20:52:00Z2712d861e120d0622fec4591b255cc075c7046d4c801e7fc4f650074f385e48c
AI agentsAI-generated codeAppSecCursorLLMSnykTesslagent skills registryapplication securityattack surfacedynamic testinginnovation huboffensive testingsecurity scanningsupply chain securityundocumented APIs

What happened

Snyk blog posts (Mar 17–20, 2026) highlight the security implications of AI-generated code and AI agents: arguing for combining static analysis with offensive dynamic testing to determine real exploitability, reporting that ~62% of LLM-generated code tests as insecure, and warning that AI agents/undocumented APIs enlarge the attack surface. Snyk describes partnerships and tooling to mitigate risk — e.g., a Tessl registry integration that attaches Snyk security scores to public agent skills, Cursor’s security agents that review ~3,000 PRs/week and surface ~200+ vulnerabilities, and a new San‑Fr

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
2712d861e120d0622fec4591b255cc075c7046d4c801e7fc4f650074f385e48c
Enrichment time
2026-03-22T20:52:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.