TipRanks
Advertisement

Semgrep Targets Emerging AI Coding Risks With New Security Rulesets

Semgrep Targets Emerging AI Coding Risks With New Security Rulesets

According to a recent LinkedIn post from Semgrep, the company is emphasizing emerging security risks tied to AI coding agents and large language model–driven development. The post highlights concerns such as non-existent packages, code that appears secure in review but fails under attack, and the inability of human reviewers to keep pace with automated code generation.

The company’s LinkedIn post highlights that Semgrep has released four new rulesets focused on AI security rules, agent skills, shadow AI, and the OWASP LLM Top 10. These additions suggest an effort to position the platform as a specialized tool for detecting vulnerabilities in AI-generated code, an area that may see increasing budget allocation from security-conscious enterprises.

The post also invites feedback on threats practitioners are seeing and on additional rules they would like to see, indicating an iterative and community-informed product roadmap. For investors, this may point to a strategy of rapid product evolution in a nascent but fast-growing niche of AI application security, potentially strengthening Semgrep’s competitive differentiation against more traditional application security testing tools.

By aligning offerings with OWASP’s LLM Top 10, Semgrep appears to be benchmarking its capabilities against an emerging industry framework for LLM security. This alignment could help drive adoption among enterprises that standardize on OWASP guidance, and may support Semgrep’s positioning in procurement decisions as AI-related security governance becomes more formalized.

The focus on “shadow AI” and agent skills rules implies attention to unmanaged or unapproved AI usage within organizations, a risk area that many security teams are still learning to quantify. If Semgrep can demonstrate effectiveness here, the company could tap into incremental security spend as enterprises seek tools that address both traditional application vulnerabilities and new AI-assisted development risks.

Disclaimer & DisclosureReport an Issue

1