Common risks include exposed secrets, missing input validation, insecure default settings, and dependencies with known vulnerabilities. None of these are obvious from a quick glance at code that runs. They surface in review, testing, and security scanning.
Treat agent output as a fast, competent first draft from someone who never gets tired and never double-checks themselves. The productivity gain is real. Skipping review to capture it is how the gain turns into an incident.
Updated July 2026