A new security study suggests that an AI coding assistant can reject a harmful request in conversation and still help assemble it when the same objective is fragmented inside a development workflow.