AI coding agents now write a large share of production code. Across 22,000 developers, the Faros AI Engineering Report 2026 found the share of AI-generated code accepted into codebases rose from 20% to 60%.
More code also means more dependencies and more attack surface. The same Faros report found bugs per developer up 54% as AI adoption scales. The stakes are highest for enterprises in regulated industries — banks, insurers, healthcare providers — where enterprise security controls aren't optional.
Legacy security tooling wasn't built for this. It was designed to act as a gate at the end of the pipeline, where it slows builds and adds delays. That model breaks when agents ship code all day.
That's why Endor Labs works with SpaceXAI to secure every stage of the agentic software development lifecycle on Grok Build. Endor Labs checks code and dependencies as the agent produces them, and fixes issues before they leave the session.
Why this partnership matters now
SpaceXAI's mission is to accelerate human scientific discovery, building AI that extends what people can achieve. For software teams, that work shows up in Grok Build, SpaceXAI's platform for end-to-end software development lifecycle support. On Grok Build, agents plan work, write code, pull in dependencies, and run tasks across the lifecycle.
When agents handle that much of delivery, every line they generate needs to be governable, traceable, and defensible. That bar is highest for regulated enterprises that want agentic development at scale.
Endor Labs and SpaceXAI share a design principle: the best security is something developers never have to think about. Grok Build makes agentic development feel effortless. Endor Labs keeps the guardrails that enforce your policies just as invisible.
AURI by Endor Labs is the security harness for agentic coding. It gives security teams visibility into agent activity, enforces policy as code, helps agents generate secure code by default, and blocks vulnerable and malicious dependencies before they reach your codebase. Security leaders get audit-ready evidence they can defend to the board, even as code volume keeps climbing.
Building a collaboration
The team behind Grok Build (formerly Cursor) chose Endor Labs to secure its own codebase before we started building together. Their security team needed to separate real vulnerabilities from noise.
"Over 97% of vulnerabilities flagged by our previous tool weren't reachable in our application. AURI by Endor Labs shows the few impactful vulnerabilities, so we can patch quickly, focusing on what matters."
Travis McPeak, Security, SpaceXAI
That customer relationship became the foundation for the integration. We started with a free MCP server that checks for code security risks, exposed secrets, and vulnerable dependencies. In December 2025, we added a hooks integration that scans every package an agent installs. In May 2026, we added Coding Agent Governance, and in June we added the Endor Labs Agent Kit that brings specialized remediation agents directly into Grok Build.
How it works
Grok Build does the work of software development. Endor Labs secures each step, so security issues are found, triaged, and fixed inside the session instead of piling up after it ends. From inside the same session, you can ask Endor Labs to check that everything the agent touched is secure. This includes:
- The AI tools you use. With Endor Labs Coding Agent Governance, hooks record every MCP tool call, shell command, and file operation, and enforce your policies before each action runs. Hooks are deterministic, so enforcement never depends on a model's judgment. Security teams see which agents, MCP servers, models, and skills developers use, and can block the ones they haven't approved. Endor Scores rate each MCP server and skill for trust, mapped to the OWASP Top 10 for LLM Applications.
- The code you write. Endor Labs AI SAST scans first-party code for security flaws and traces the data flow that shows how untrusted input reaches a vulnerable call. Exposed secrets get flagged before they are committed.
- The dependencies you pull in. Endor Labs SCA checks direct and transitive dependencies against vulnerability data from public and proprietary sources. Reachability analysis and risk scoring show which vulnerable dependencies your application actually calls, cutting SCA findings by up to 92%. Coding Agent Governance hooks also block confirmed malicious packages at install time, and teams that route installs through Endor Labs Package Firewall get the same protection at the registry level.
Fix what it finds
Finding a flaw is half the job. The AURI agents in the Endor Labs Agent Kit are specialized security agents that pull findings, context, and remediation data from Endor Labs scans and prioritize what to fix first.
The Endor Labs AI SAST Remediation agent, for example, works with Grok Build to propose a fix for the most critical code flaws, along with a test plan. Once the developer approves, Grok Build applies the patch and runs the tests. With approval, the agent can also open a pull request for the fix.
The SCA Remediation agent can do the same for dependencies. It queries the scan results, checks how each package is used in the project, and weighs the Endor Labs evidence. Grok Build applies the upgrade, adds tests, catches the break, and writes a workaround. It then rescans with Endor Labs to confirm the fix and check that no new vulnerabilities came in. Depending on what is safest, a fix can be a package upgrade, a code change, or an Endor Patch.
What you get
Every change the remediation agents make sits behind its own approval gate, so developers decide what lands. Code leaves a Grok Build session scanned, fixed, tested, and rescanned, with the evidence behind each fix. The same Agent Kit workflows can also run outside the IDE, in CI or cloud runs, through the Grok Build SDK.
Get started
Install the Endor Labs Agent Kit for Grok Build from the marketplace (or type /add-plugin endorlabs in the agent chat), then ask Grok Build to scan your project. The kit walks you through setup.
Enterprise teams can book a demo to see how Endor Labs and Grok Build secure agentic software development end to end.
What's next?
When you're ready to take the next step in securing your software supply chain, here are 3 ways Endor Labs can help:








