Work in progress · updated 30 Sep 2026 · notes, not conclusions
When another AI asks your product
When the user of your security product is another AI, what does a good answer look like?
For exampleA developer's coding agent asks your product: "Is this cloud storage bucket exposed?" There's no screen. The answer has to carry the verdict, the evidence and the safe next step, in words another agent can act on.
- A coding agentasks: is this bucket exposed?
- Your productanswers with no screen
- The answerfour slots, always in this order
- Verdict exposed
- Evidence a public link, 3 files
- Confidence rule-based, not a guess
- Safe next step make it private
Why it matters
More questions to security products will come from agents inside developers' tools. A vague or over-confident answer there gets acted on automatically. The words, severity and evidence need the same care as a screen.
What I'm trying
- Three tool descriptions for a made-up vendor: what the product can answer, and when it should refuse.
- Answer shapes: verdict, evidence, confidence, and the one safe action, always in the same order.
- A test: 20 real-looking prompts from a coding agent, counting how often the task ends correctly.
What would show it works
A published task-success count on the made-up vendor. Once that page exists, this becomes an add-on to the pilot.
Next step
Write the three tool descriptions and run the first 20 prompts.