Skip to content
Artwork for Insecure Agents
NewsTech News

Insecure Agents

Allie Howe

Insecure Agents lives at the intersection of AI engineering and security. Stay ahead of the curve with expert insights, real-world incidents, and bold ideas for safer agents.

Play
  • 30 episodes
  • weekly
  • Avg 37 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • July 14 · 44 min

    Skills Are the New Code: How We Secure the Context Our Agents Consume, with Guy Podjarny (Tessl)

    Guy Podjarny built Snyk into the company that taught developers to secure their dependencies. Now, with Tessl, he argues that agent skills have become a new unit of software, one that deserves the same rigor we give source code. Guy Podjarny, founder of Tessl and Snyk, joins us to explain why skills are the new code: context is the only layer that runs straight inside the model's reasoning loop, so it is effectively the programming language for models. We get into the new supply chain that follows (there are already 2 million skills in the open ecosystem, up from near zero last September), why a malicious or negligent skill is so hard to catch, why there's still no npm or PyPI for skills, and why enforcement is moving into the harness because the model cannot police its own context. Guy also makes the case that skills rot, so a skill you write today can be useless or harmful three months from now without a plan to maintain it.

  • June 29 · 39 min

    The Grant Behind Enterprise Managed Auth for Claude: ID-JAG with Karl McGuinness (ex-Okta)

    Every SaaS app an enterprise connects to stands up its own OAuth stack of long-lived grants the enterprise can't see or revoke. Karl McGuinness, author of ID-JAG and past Chief Product Architect at Okta, calls these "OAuth islands," and agents turn them from a nuisance into a serious risk. He joins us to explain OAuth federation, how ID-JAG shipped inside Anthropic's Enterprise Managed Auth for Claude, and what it really takes to govern agent access from one central checkpoint.

  • June 26 · 39 min

    One Harness, Zero Standing Secrets: Derek Meegan (Browserbase) on Building bb

    This is one of the best public internal AI stories we've seen, built by just a few engineers. Derek Meegan, a software engineer at Browserbase and the lead behind their internal AI agent, bb, joins us to explain how bb took feature-request coverage to 100% with zero human effort, got 99% of support first responses under 24 hours, and turned 30 to 60 minutes of manual log-diving into a single Slack message. Then we get into the part most teams skip: the security model that lets you actually trust an agent with that much reach. Derek covers code mode, the sandbox that never touches a secret, credentials brokered just-in-time through an integration proxy, least-privilege tools on every event-driven trajectory, and permissions computed per invocation instead of written into a static config. His thesis: use the agent to take the repetitive, well-understood work off people's plates, and make the harness verifiably secure, because security is what lets you scale it.

  • June 24 · 34 min

    It's the Harness, Not the Model: David Cramer, CPO of Sentry, on Agents, Expectations vs Reality

    David Cramer, CPO and co-founder of Sentry, joins us to cut through the agent hype with a working engineer's skepticism: the model is rarely what holds agents back. The harness you build around it is. We get into the Railway incident, where a coding agent found a stray CLI token and deleted a production database (and every backup) in nine seconds, and why the enforcement layer has to live below the agent, not in an advisory system prompt. David explains Seer, Sentry's AI debugger, as the counter-example: an agent doing real work because it was given the right context, not more autonomy. He also walks through Warden, the code-review harness he built that found 100+ previously unknown vulnerabilities across Sentry and open-source projects, including full auth bypasses, for roughly $1K of compute. We also get his contrarian-but-consistent take on why MCP is not just a shim on your API, why CLIs are harder to secure than people think, and why verification, not code generation, is still the unsolved problem.

  • June 22 · 35 min

    From Spec to Standard: How AARM Became the Conformance Bar for Agent Runtime Security, with Herman Errico (Vanta, AARM))

    Herman Errico, Product Manager for Technical Research at Vanta, joins us to discuss AARM (Autonomous Action Runtime Management), the spec he created to define a brand-new security category for agents that take real actions, not just generate text. We get into why the action boundary is the security boundary, why securing the model, prompt, or orchestration layer is the wrong place to enforce, and why a runtime needs five authorization decisions (allow, deny, modify, step-up, and defer) instead of a binary yes or no. Herman also explains why he didn't ship a product but a spec, then donated it from Vanta to the Cloud Security Alliance so the industry can compete on execution instead of marketing, how to reason about which context an agent can trust, and why you must block the action from occurring before it takes place.

  • June 18 · 32 min

    Self-Driving Infrastructure Starts with Security: Malte Ubl, CTO of Vercel, on Vercel's New deepsec Security Harness

    Malte Ubl, CTO at Vercel, joins us to discuss deepsec, Vercel's open-source AI security harness designed to scan entire codebases for vulnerabilities using coding agents like Claude and Codex. We explore why software engineering is shifting from programming models to programming agent harnesses, how deepsec scales security reviews across millions of lines of code, when AI token spend is justified, and why Vercel is betting on AI Gateways, microVM sandboxes, and self-driving infrastructure to power the next generation of software development.

  • June 16 · 37 min

    Governing AI Agents Means Governing Intent: The AWARE Framework with Sunil Agrawal, CISO of Glean

    Sunil Agrawal, CISO at Glean and one of the authors of the AWARE Framework, joins us to discuss the new guide for governing generative and agentic AI he co-authored with Palo Alto Networks and Databricks. This framework gives CISOs a much needed playbook in a rapidly evolving threat landscape. Palo Alto's Unit 42 showing AI-assisted attacks can now reach data exfiltration in as little as 25 minutes, leaving defenders almost no time to respond.We dig into AWARE's five behavioral dimensions, why governing modern AI means controlling intent and context rather than just access, how to give every agent a scoped identity instead of shared credentials, and the cascading risks that emerge when agents start delegating to other agents.

  • June 15 · 29 min

    A Dangerous Precedent Set? The US Government Yanks Fable

    Alex Stamos, CPO of Corridor and past CISO at Facebook, and Andrew Becherer CISO at Socket, join us to discuss the open letter they and 100 others have signed in opposition to the US government taking down Fable after research from Amazon showed capabilities that gave the current administration pause. We discuss the potentially dangerous precent this sets, the state of the letter, and what to do while waiting for Fable to come back online.

  • June 8 · 38 min

    Auth Is Hard (And Agents Make It Harder) with Damian Schenkelman, Auth0

    Why does every AI security incident seem to trace back to auth? We sit down with Damian Schenkelman, VP of Research and Development at Auth0 to discuss⁠ recent incidents in the news, MCP, the act claim chain, and the future of agent identity. The conversation digs into the core problem agents create: when an agent hands a task to a sub-agent, which calls an MCP server, which hits a SaaS API, who is actually making this call, and on whose behalf?

  • June 3 · 41 min

    AAuth: Moving Beyond OAuth and the Future of Agent Auth

    In this episode we sit down with Dick Hardt, the creator of OAuth, to talk about why the auth primitives we built for the web fall apart the moment agents start acting on our behalf. We dive in to why OAuth doesn't fit MCP, what breaks when an agent runs for hours and touches a dozen systems using your credentials, and his new protocol, AAuth: a way for developers to run agents without API keys.

Showing 21–30 of 30 episodes