As coding agents become more autonomous, security teams need more than permission prompts. They need visibility into what agents can access, and deterministic controls over what they can do.
The report examines an important change in how Claude Code handles permissions and the broader governance implications as coding agents take more actions without requiring a developer to approve each one. Gartner also includes Endor Labs in its discussion of vendors building controls around coding-agent actions.
We think the bigger story goes well beyond a single setting in Claude Code.
Coding agents are quickly moving from tools that suggest code to systems that act on a developer’s behalf. They read files, execute shell commands, install packages, invoke MCP tools, modify repositories, and interact with other systems using the permissions available in their environment.
As that autonomy increases, the security model has to change with it.
Permissions define the blast radius
A coding agent can only do what its environment allows it to do.
That makes permissions one of the most fundamental controls in the agentic development stack. Which files can an agent read? Which credentials can it access? Which MCP servers and tools can it invoke? Can it install software? Can it touch production infrastructure?
The narrower those permissions are, the smaller the blast radius when an agent makes the wrong decision or acts on malicious input.
But permission boundaries alone aren't enough.
Giving an agent access to the shell may be necessary for it to do useful work. Giving it repository access may be the entire point. The harder question becomes whether a specific action should be allowed at the moment the agent attempts it.
That is where hooks become important.
Hooks put policy inside the agent loop
Skills, MCP servers, and prompts can tell an agent how you want it to behave. Hooks let you enforce what it is actually allowed to do.
A hook executes at a defined point in the agent lifecycle, before a consequential action reaches the underlying system. The model can decide it wants to run a command or call a tool; the hook can independently decide whether that action should proceed.
That's an important distinction.
A skill is something an agent can use. An MCP server gives it additional capabilities. Instructions influence how the model reasons. A hook sits on the execution path itself.
For security teams, that creates a deterministic enforcement point where policy can allow, block, or escalate an action before it happens. We've written previously about why we believe hooks are becoming a control plane for the agentic development lifecycle.
From a hook to Coding Agent Governance
Of course, wiring up a hook on one developer laptop isn't the same thing as governing coding agents across an enterprise.
That's the problem we built Endor Labs Coding Agent Governance to solve.
Endor Labs gives security and engineering teams visibility across the agentic development stack: the coding agents developers use, the models behind them, the MCP servers they connect to, and the skills and hooks running in those environments. Teams can then enforce centralized policies over agent behavior rather than relying on every developer to configure every agent correctly.
Policies can govern consequential actions including:
- Shell commands and file access, such as preventing destructive commands or attempts to read credential files.
- MCP tool calls, so an approved MCP server does not automatically mean every action exposed by that server should be allowed.
- Prompts and skills, giving teams visibility into the instructions and capabilities influencing agent behavior.
- Package installation, where Package Firewall can stop malicious or otherwise disallowed packages before they reach the developer environment.
Endor Labs can block actions in real time or record them for review, with activity tied back to the agent and user responsible for it.
Give agents security capabilities, too
Governance is only half of the problem. You also want coding agents to have access to the security context they need to produce better software in the first place.
That's why we've made Endor Labs available directly inside agentic coding workflows through plugins, skills, and our MCP server. Developers and agents can detect and remediate vulnerabilities, exposed secrets, vulnerable dependencies, and malicious packages without leaving the environment where the code is being written. AURI Agents can also run security workflows such as vulnerability triage and remediation directly inside supported coding tools.
These two layers are complementary: MCP, plugins, and skills give coding agents security capabilities. Coding Agent Governance controls the capabilities and actions agents are allowed to exercise.
And because both connect back to the Endor Labs platform, organizations don't have to treat agent behavior and application security as separate problems.
Secure the actions agents take and the code they produce
The shift toward autonomous permissions is another sign of where software development is heading.
Coding agents will ask developers for permission less often. They'll take on larger tasks. They'll interact with more tools and systems. And increasingly, they'll operate with many of the same privileges as the developers they work for.
Security therefore has to move into the agent loop itself: limiting what agents can access, enforcing policy before consequential actions execute, and securing the code and dependencies they produce.
That's the premise behind Endor Labs Coding Agent Governance: govern the actions coding agents take, and secure the code they write, from a single control plane.
What's next?
When you're ready to take the next step in securing your software supply chain, here are 3 ways Endor Labs can help:
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.