Anaconda Puts Coding Swarms and Attack Agents on the Same Python Stack

Models & Agents
Anaconda's October 6 release puts coordinated coding agents in Visual Studio Code next to a security test that tries to make those AI systems misbehave before the work ships.
By Shashi Bellamkonda · October 6, 2026
20 years
IntraPhone backlog, customer account
300+
attack categories in the Enkrypt test
73%
of scanned tool servers had vulnerabilities, Enkrypt reports
Oct 15
Anaconda Scale, virtual conference
Kilo coordinates the coding agents. Enkrypt tests the AI and can block a risky action. Outerbounds carries the workflow into production.

Robert Björne, product owner at IntraPhone, said in Anaconda's October 6 release that Kilo took his team from being blocked by two decades of backlog to "running out of tickets." The constraint, he said, is no longer the old queue. It is how much one person can handle. He sees agent swarms as the way to run several of those workstreams at once.

On October 6 in Austin, Anaconda announced new capabilities across its platform, pairing those coding agents with AI security testing and runtime controls. David DeSanto, the chief executive, said customers can secure as fast as they build. The expansion draws on three acquisitions this year. Anaconda bought Outerbounds in April for the production workflow, Kilo Code in July to coordinate the coding agents, and Enkrypt AI on August 4 for the security test and the guardrails. I wrote about the Outerbounds deal in April.

One agent maps the login, and the next writes the test

Although Anaconda's October release describes swarms reaching Visual Studio Code for the first time, Kilo documented the feature under Experimental settings on September 14. In Kilo's example, one agent maps how the login works and posts a note on a shared board. A second agent reads that note and writes the test.

Kilo says HOLD and VETO messages on that board are advisory. They do not stop a running agent. Separately, Anaconda says Enkrypt's guardrails can approve, modify, or block a risky action while the agent is running. A pilot should show how those two controls apply to the team's own workflow, because the public pages do not yet join them.

Kilo Desktop, marked beta on the launch page, lets a person and an agent edit and run notebook cells in the same session. Anaconda had already reported access to more than 500 models, including models that run on the company's own computers, in its September 29 announcement. The October release also lists 77 checked open-source models and 13,000 newly checked packages. Eligible ChatGPT Plus and Pro users can apply the OpenAI models included in their plan inside Kilo, without a separate OpenAI API key and without paying for that usage again.

Enkrypt tries to make the AI do something unsafe

Enkrypt's agents try to make a model, an agent, an application, or a tool connection do something unsafe, across more than 300 attack categories. A normal code review still belongs to the team. This test checks the AI.

Anaconda says Enkrypt scanned 268,210 tools on 25,264 servers and found vulnerabilities on 73 percent of those servers. The servers use the Model Context Protocol, a standard way for AI applications to connect to tools and data sources. The finding applies to Enkrypt's scanned sample, not necessarily every server that uses the protocol. Anaconda's survey says 63 percent of the people who answered are moving toward swarms. An Agent Incident Registry lists public agent incidents and names the sources.

Cursor, GitHub Copilot, and Claude Code also let agents work in parallel. Anaconda is adding its package library, a choice of local models, and the Enkrypt test on the same path. The company says more than 1.2 million organizations use it, including 95 percent of the Fortune 500.

Ask Anaconda which agent changed the file

In a pilot I would ask Anaconda to show which agent changed each file, which tool it called, and which permission allowed it. I would also ask where a person approves the change, and what the team does when an agent gets the login wrong. Anaconda Scale, the virtual customer conference, is on October 15.

CIO question
After the agents finish the tickets, can your team name which agent changed which file, and which control applied?
Sources
Anaconda. "Anaconda Brings Agent Swarms and Autonomous Red-Team Agents to the AI Dev Factory." Anaconda, 6 Oct. 2026, www.anaconda.com/press/agent-swarms-red-team-agents-ai-dev-factory.
Anaconda. "Introducing the Expanded Anaconda Platform." Anaconda, 6 Oct. 2026, www.anaconda.com/products/launch/2026-october.
Kilo. "New in Kilo for VS Code: Swarm, Browser Use, and GitHub in Agent Manager." Kilo, 14 Sept. 2026, blog.kilo.ai/p/swarm.
Anaconda. "Anaconda's Kilo Partners with OpenAI to Bring Sign in with ChatGPT to AI Builders." Anaconda, 29 Sept. 2026, www.anaconda.com/press/kilo-openai-sign-in-with-chatgpt.
Bellamkonda, Shashi. "Anaconda Just Bought the Half of the AI Stack It Never Owned." shashi.co, 29 Apr. 2026, www.shashi.co/2026/04/anaconda-just-bought-half-of-ai-stack.html.
Disclaimer: This blog reflects my personal views only. Content does not represent the views of my employer, Info-Tech Research Group. AI tools may have been used for brevity, structure, or research support. Please independently verify any information before relying on it.