Almost overnight, your developers are running AI coding agents like Claude Code, Cursor and Codex. Each one installs MCP servers from public registries, loads skills, executes shell commands, reads your source code and calls external models, usually with no security team in the loop. A typosquatted MCP server, a skill that quietly reads your credentials, a tool description carrying a hidden prompt injection, an agent one command away from wiping a disk: it is a real and ungoverned attack surface, growing inside your own organization. And it does not stop at AI. The same machines pull in npm and PyPI packages, browser extensions and IDE plugins by the thousand, any of which can be the way in. The development environment has never been this powerful, or this exposed.