This makes me think: apparently we can't just make agents write secure code, so there's a separate step to scan for vulnerabilities.
What else could be currently lumped into the "coding" task, done poorly and perhaps also requiring another step? Performance?