Defender LLMs without human in the loop are just another prompt injection (AI phishing) and DoS attack vector.
Any meaningful mitigation capability you give them is also a capability to do damage.
If they can only deploy package updates that's not meaningful because you could do that on a cronjob too. And even something as simple as a circuit breaker can turn into a DoS.
Attacker-GLM: "Defense also GLM. Request to help peer."