AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Evaluating and Preventing Security Smells in AI-Generated Ansible Code

arXiv · AI, language, vision and robotics · article · Aug 25, 2026 · UTC

AI coding assistants generate Infrastructure as Code, yet no work has examined whether this code meets security requirements. This matters because security smells in infrastructure code propagate to deployed systems, producing infrastructure that is insecure and untrustworthy. We evaluate 16 AI models generating Ansible roles for Apache Tomcat v10 and MongoDB v7, analysing 278 Ansible roles against CIS benchmarks. Without security guidance, all 16 AI models produced code containing security smells, resulting in vulnerable infrastructure that fails compliance verification and underperforms code

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-21T10:02:02.728Z. This is not the publication date.