Product & Open Source Blog
Agentic Control for Software Engineers
An enterprise-grade control layer on top of coding agents, keeping engineers in control without giving up the speed of auto-approval.
Read more
Product & Open Source
Research Who is profiling whom: what attackers fear about AI correlation
A Russian-language cybercrime thread shows attackers fragmenting malicious work across models and accounts to slip past per-request AI controls — and fearing the one thing that defeats it: correlation across behavior, identity, and context.
Product & Open Source Angry Bear: Enforcing the Skills Your Coding Agent Keeps Forgetting
Angry Bear is Bluebear's open-source pre-tool-use hook that blocks AI coding agents from editing files until the required skills are loaded, turning 'please follow the conventions' into a precondition. MIT, works with Claude Code and Cursor.
Product & Open Source Bear Metal: The Coding Agent We Point at Our Own Backlog
Bear Metal is Bluebear's open-source background coding agent: it works tickets delegated through Linear and opens pull requests through your GitHub App installation.
Research The mandate gap: the agent risk your security stack can't see
Coding agents introduce a new class of risk: the gap between what a user authorized and what the agent actually did. Why your existing controls miss it, and how to govern intent instead of just actions.
Research The Missing Dependencies Hidden Inside AI Agent Skills and Plugins
We found 72 exported AI agent skills and plugins referencing package names that do not exist, creating an opening for slopsquatting attacks across npm, PyPI, and Cargo.
Product & Open Source Baloo: The Code Reviewer We Built for Our Own Agents
Baloo is Bluebear's open-source GitHub App for self-hosted AI pull request review, built from the agent we used to review our own agent-generated code.
Research The Hidden Git Branch That Leaked 20,000+ AI Coding Sessions
While tracing the source of an AI coding-agent dataset, we found 20,000+ agent sessions exposed through public Git branches, including API keys, credentials, infrastructure details, and screenshots.
Research It's Not What the Model Writes. It's What the Agent Runs.
Recent threat intelligence details how cybercriminals are using headless coding agent frameworks on compromised hosts to automate source code exfiltration.
Research The Hidden Attack Surface Inside Every Coding Agent
Most teams still talk about coding agents as if they're just LLMs that write code. That misses the real security picture.
Research The Credentials Your AI Agent Sees (And Why You Should Care)
AI agents increasingly need credentials to act on our behalf, and by doing that are quietly turning local configuration files and shell profiles into a secondary, high‑risk credential store. That creates a new security boundary, a phenomena we call context‑window credential drift
Research The Coding Agent Ecosystem Is Now a Target
Attackers aren't just targeting what coding agents do — they're going after the entire ecosystem around them. InstallFix is only the latest example.Ready to start securing your AI agents?
©2026 Bluebear Security Inc. All rights reserved. · info@bluebear.io · (929) 702-2605 · Privacy