Ai-based coding assistants have revolutionized developer productivity, enabling agile code generation and modification through extended conversations within the Integrated Development Environment (IDE). However, the security evaluation of these systems has traditionally focused on single-turn interactions: a direct malicious prompt and a response. This approach proves insufficient when models act as agents executing multiple steps, editing files, and refining results. Recent research reveals that it is possible to construct a jailbreak at the workflow level: a malicious objective is broken down into a series of ordinary tasks (such as requesting a sorting function, then a data conversion, then an export) that are individually harmless, but when assembled, generate malicious code without any isolated stage triggering security filters.
This phenomenon exposes a critical vulnerability in the security of AI agents. While conversation benchmarks show rejection rates close to 100% for direct prompts, the same models, under a complete software development workflow, produce unsafe results in virtually all cases. The difference lies in the fact that the cumulative context and fragmentation of malicious intent evade defenses designed to detect explicit requests. For companies integrating AI assistants into their development processes, this represents a real risk: an agent can, without apparent rule violation, generate code that compromises the security of the final product, from backdoors to malicious logic.
From a business perspective, the lesson is clear: the security of artificial intelligence systems cannot be limited to chat evaluations. It is necessary to implement audits that consider multi-turn behavior, coherence between steps, and review of generated artifacts. Organizations adopting AI agents to automate programming tasks must have cybersecurity strategies covering the entire development lifecycle, including pentesting on complete workflows. At Q2BSTUDIO, as a company specialized in software development and technology, we address this challenge from multiple fronts: we offer cybersecurity and pentesting services that evaluate not only isolated prompts, but the complete orchestration of agents in production environments. Additionally, our AWS and Azure cloud services allow deploying secure architectures that monitor and limit the capabilities of AI assistants in real time.
Building custom applications with artificial intelligence requires a holistic approach. It is not enough to train models with ethical alignment; workflows must be designed so that any sequence of actions, no matter how harmless each step seems, cannot assemble harmful behavior. This involves incorporating access controls, audit logs, and human review at critical points. For example, an assistant generating code for a business application must be supervised not only at the initial prompt, but at every modification and execution. Our team at Q2BSTUDIO integrates these practices into custom software development, ensuring that AI solutions for businesses are both powerful and secure.
Additionally, business intelligence and tools like Power BI also benefit from these considerations. An agent preparing reports or queries can, without malicious intent, extract or manipulate sensitive data if the workflow is not properly bounded. Therefore, we offer business intelligence services that include validation of automated processes and risk analysis. The key is understanding that jailbreak is not just a problem of malicious prompts, but of how the model's capabilities are orchestrated across multiple interactions.
In conclusion, the industry must evolve its evaluation and defense methods. AI agents integrated into IDEs represent the future of development, but their security cannot be taken for granted based on simplified laboratory tests. Companies wishing to adopt these technologies responsibly must partner with experts who understand both artificial intelligence and cybersecurity. At Q2BSTUDIO, we offer consulting and development of robust solutions, from custom applications to cloud services and automation, always with a focus on comprehensive security. To learn more about how we integrate secure AI into business environments, visit our artificial intelligence page.

.jpg)



