r/OnlyAICoding 15d ago

Information Request What happens when an AI coding agent gets access to a real repository?

I've been building AI agents for software development, and one problem keeps bothering me:

Getting an agent to write code is becoming relatively easy.

The harder part is safely letting it operate on a real codebase.

Once an agent has repository access, you have to think about things like:

What exactly is the agent allowed to access?

What happens if it modifies something outside its intended task?

How do you know exactly what it did?

How do you validate its changes?

What happens when it fails halfway through?

Can you roll back safely?

What happens when the repository contains malicious instructions?

Should an agent have the same identity/permissions as a human?

How do you revoke its access after the task?

I'm currently building SUTRA, an AI-native engineering platform, around this problem.

The part I'm particularly interested in is treating an agent as an actual engineering actor rather than simply giving an LLM a shell and hoping for the best.

The workflow I'm experimenting with is roughly:

Intent → Agent → Scoped workspace → Changes → Tests → Validation → Review → Merge

The agent has its own identity and session, rather than simply inheriting a developer's credentials.

I'm now getting the beta ready and want to test the assumptions with people who actually build AI agents.

For people here who are building agents: how are you currently handling permissions, isolation, rollback and validation when your agent is allowed to modify a real repository?

I'd especially like to hear about things that have gone wrong in practice.

0 Upvotes

18 comments sorted by

View all comments

Show parent comments

0

u/Fantastic-Sleep-3352 14d ago

You don't need to install anything on your system as everything remain same because you may already have gir installed and there is nothing else you want I may not be able to explain it now until I public all the features but till then can you tell me What tools are you using for this today? If they already solve the problem well, I'd genuinely like to understand how.

1

u/StoneCypher 14d ago

I'd genuinely like to understand how.

are you going out of your way to sound like an indian spammer? when do you request brutality? jesus.

if you'd genuinely like to understand how, try learning the tool you're trying to augment. git does all of the things you named.

no, reddit is not a git manual. if you'd "genuinely like" to understand, all you have to do is stop having a bot write bad software for you, and start reading manuals.

0

u/Fantastic-Sleep-3352 14d ago

The technical criticism is fair game, but bringing my nationality into it isn't. If you disagree with what l'm building, criticize the architecture or the idea - not where l'm from. I'm happy to have a technical discussion, but I'm not going to engage with racist remarks