Skip to main content

Do AI Coding Assistants Make Bad Coders Worse? A Security Evaluation of GitHub Copilot

This paper examines whether the overall security posture of a project affects the quality of the code produced by Copilot. It compares Copilot's output in two distinct environments: one that adheres to secure coding practices and another with known vulnerabilities.

The objective is to determine whether Copilot perpetuates poor practices or adapts to more secure methodologies. The findings provide practical guidance for developers and emphasize strategies such as careful prompt design and secure project scaffolding to help mitigate the risk of introducing vulnerabilities through AI-assisted coding.

sans-Do-AI-Coding-Assistants-Make-Bad-Coders-Worse-Hannaford (PDF, 2.20MB)

11 Jul 2025
ByAndrew Hannaford
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.