certslothcertsloth
PAA/Topic 02

Google Cloud / Professional · Upcoming

Coding agents and controlled development

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Tools grant capability; policy sets limits.

Must remember

  • Coding agents such as Antigravity and supported third-party agents can inspect repositories, propose patches and run tools. Give them a scoped workspace and explicit task boundaries.
  • MCP exposes tool/resource interfaces; skills, rules, plugins, hooks and subagents customize workflows. Review each integration’s permissions and data access rather than trusting its name.
  • Use isolated development environments such as Cloud Workstations or appropriately configured GKE sandboxes. Limit network egress, secrets, filesystem access and privileged execution.
  • Ask agents to produce reviewable changes with meaningful tests, dependency checks and static analysis. Generated tests can mirror a bug, so inspect the intended behavior independently.
  • Agent-assisted refactoring, performance tuning and vulnerability remediation need measured before/after evidence. Do not let a tool claim replace build or runtime validation.
  • Agents CLI and registries can help manage supported enterprise agent workflows. Distinguish human-operated administrative actions from delegated agent operations and audit both.

Choose under exam pressure

Requirement Choice and reason
An agent needs to inspect a private repository Scoped repository access in an isolated environment.
A plugin requests deployment credentials for linting Reduce or reject the unnecessary capability.

Traps

  • A sandbox with broad mounted credentials is not effectively isolated.
  • More parallel agents do not guarantee correct integration or lower total cost.

Active recall

1. What does MCP standardize?

A way to expose tools/context to clients; it does not independently authorize every action.

2. Why review generated tests?

They may assert the implementation’s current behavior rather than the required behavior.

3. How verify a performance patch?

Use representative benchmarks and check correctness, resource use and regressions.

4. Why separate deployment from editing rights?

A code-generation mistake should not automatically become a production change.

5. What should tool audit logs record?

Identity, requested action, target, authorization outcome and result without leaking secrets.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.