Software development is moving from a code-centric activity toward an intent-driven engineering process, a shift often described as "vibe coding". While this transformation creates significant speed and productivity opportunities for the defense industry, working code is not always safe code.
In this article, VISTA Lab Researcher Aleyna Hafızoğlu explores the evolution from AI-assisted coding to agentic workflows. She details why vibe coding must be combined with human oversight, security testing, and risk-based governance layers—such as Rules, Skills, and the Model Context Protocol (MCP)—to build secure and reliable defense software.