Cognition, Semgrep, Factory and Composio

The Future of Agentic Engineering | Cognition (Devin), Semgrep, Factory & Composio | $1.2B+ Raised

AI agents are everywhere right now. But are they actually working inside real engineering teams?

At AngelList’s Founders Cafe, I sat down with founders of Cognition ($898M raised), Semgrep ($204M raised), Factory ($70M raised), and Composio ($29M raised) to talk about what agentic engineering looks like in practice.

There’s a lot of hype around AI coding tools, but the reality is more nuanced. Some teams are moving 10x faster, others are slowing down. A big part of it comes down to whether your codebase is actually “agent-ready” (linting, type systems, guardrails, etc).

We also went deep on security, which is one of the biggest gaps right now. As more non-developers start “vibe coding,” the risk surface grows fast. We talked about MCP access control, layered security, and why you can’t rely on models alone to generate secure code.

Enterprise teams are also dealing with the operational side of this shift. They have to manage cost, run evals, and help thousands of engineers use these systems well. Tools like PR review agents, model routing, and internal orchestration are quickly becoming part of the stack.

The Future of Agentic Engineering | Cognition (Devin), Semgrep, Factory & Composio | $1.2B+ Raised
Episode still: Cognition, Semgrep, Factory and Composio

What this episode covers

A multi-company view of agentic engineering, from coding assistants to autonomous workflows and the practices teams need before trusting agents in real repositories.

Why this matters in practice

Agentic engineering changes the software-delivery control loop, making evaluation, review, and bounded autonomy as important as code generation.

Chapters

  1. 00:00Welcome and setup
  2. 00:41Panel introductions
  3. 02:00Windsurf acquisition
  4. 03:52Do agents boost productivity?
  5. 04:16Agent-ready codebases
  6. 05:55Real-world enterprise wins
  7. 07:28Agents building integrations
  8. 09:41Security risks (vibe coding)
  9. 11:04LLM security tools landscape
  10. 12:21Defense-in-depth
  11. 15:16MCP security pitfalls
  12. 18:41MCP vs CLI
  13. 23:08RL for secure code
  14. 27:05Auto research missions
  15. 27:57Training your own models
  16. 31:33Distillation and IP decay
  17. 34:50Hybrid systems
  18. 37:14Side projects vs enterprise
  19. 40:16Forward deployed engineering
  20. 40:58Agent orchestration
  21. 43:08Cost controls
  22. 43:49Auto model routing
  23. 45:52Guardrails
  24. 47:02Legacy code risks
  25. 48:16Model poisoning
  26. 49:35What is a harness?
  27. 51:47Why build your own
  28. 52:58Continuous learning loops
  29. 56:30Security workflows
  30. 57:37Validation and meta engineering
  31. 1:00:32Running evals in practice
  32. 1:03:36Teams reshaped by agents
  33. 1:12:17Should you study CS?
  34. 1:14:11Enterprise adoption
  35. 1:18:23Local to cloud journey
  36. 1:20:51Agent economy and prompting
  37. 1:22:22Spec vs plan
  38. 1:25:12Closing and thanks

Key takeaways

  • Where agentic engineering is working
  • How teams evaluate coding agents
  • Risks in autonomous software workflows
  • What production agentic engineering requires
Agentic engineering is less about replacing engineers and more about changing the control loop around software delivery.

Related topics

More episodes