AI agents are no longer just a nice-to-have in the developer toolkit. They are becoming active participants in the software development lifecycle. However, this autonomy comes with a significant catch: the attack surface is expanding exponentially as agents are adopted not just by professional engineers, but by a growing wave of “citizen developers”.