Videos cgimkNGNjvU
Agentic Development Security — Ezra Tanzer, Snyk
Scene timeline
85 shot(s).
keyframes kept every frame deduplicated
What was stored
- cues
- 295
- whisperx 295
- chunks
- 47
- from 295 cues
- keyframes
- 47
- kept of 85 captured
- frames with text
- 47
- 1,470 lines read
- chapters
- 19
- from the source metadata
- keyframe bytes
- 11.7 MB
- word timings on 295 cues
Provenance
| stage | state | model | started | took |
|---|---|---|---|---|
fetch |
done | — | 2026-08-10 04:21 | 1m 56s |
stt |
done | — | 2026-08-10 04:23 | 29s |
chunk |
done | — | 2026-08-10 04:23 | 0s |
text_embed |
done | — | 2026-08-10 19:47 | 1s |
keyframe |
done | — | 2026-08-10 04:23 | 2m 59s |
ocr |
done | — | 2026-08-10 04:26 | 21s |
frame_embed |
done | — | 2026-08-10 19:47 | 8s |
Frames, and what the machine read
-
- AlEngineer0.96
- World's Fair0.97
-
- AlEngineer0.95
- World's Fair0.99
-
- LAB & PLATINUM SPONSORS0.98
- Amazon AGI Lab0.98
- ANTHROP\C1.00
- Google DeepMind1.00
- MINIMAX0.94
- OpenAI0.92
- Akamai1.00
- arize1.00
- aws1.00
- Braintrust bright data0.99
- B1.00
- Browserbase1.00
- docker1.00
- :neo4j0.93
- ORACLE1.00
- PayPal1.00
- qodo1.00
- reducto1.00
- Sonar1.00
- Makers of0.99
- togetherai1.00
- Unblocked1.00
- WorkOS1.00
- SonarQube1.00
-
- AlEngineer1.00
- World's Fair0.97
-
- AlEngineer0.99
- ☆0.95
- 00.73
- World'sFair1.00
- Snyk Packo0.91
- Checking:0.99
- Overall: He0.93
- Security0.96
- AGENTIC DEVELOPMENT SECURITY0.99
- Gaining confidence in increasing coding agent autonomy0.99
- Ezra Tanzer1.00
- PRODUCT DIRECTOR1.00
- SNYK0.96
- Dan Arpino1.00
- STAFF ENGINEER1.00
- SWYK0.97
- snyk1.00
- 301.00
- A1.00
- $I0.69
- 米0.99
- Engineering the future of Al0.98
- World's Fair0.96
-
- AlEngineer0.99
- LY674TamatoVY/edit?slide=id.g3ef66d87504_4_24#slide=id.g3ef66d87504_4_0.98
- ☆0.70
- World's Fair0.99
- Snyk Packc0.93
- Checking:0.99
- Overalt: He0.94
- Security1.00
- + Handing a0.95
- PRESENTED BY0.98
- Dequirement0.96
- Microsoft1.00
- -WHERE IT STARTED0.97
- Q1 20251.00
- MCP releases.0.98
- Developers experiment.1.00
- No security layer.1.00
- snyk1.00
- A0.99
- $10.67
- 米0.97
- Engineering the future of Al0.99
- World's Fair0.96
-
- AlEngineer0.99
- docs.google.com/presentation/d/1IS752ciB1da4U2KUh7OI7OtnAaloLY674TamatoVY/edit?slide=id.g3ef66d87504_4_38#slide=id.g3ef66d87504_4_380.98
- ☆0.99
- 00.83
- World'sFair1.00
- Snyk Packo0.94
- Checking:0.99
- Overall: He0.93
- Security1.00
- + Handing a0.93
- EARLY 20251.00
- PRESENTED BY1.00
- Requirement o0.94
- Our first move.0.99
- Microsoft1.00
- Snyk MCP Server0.97
- Rules-based directives1.00
- Snyk's scanning tools, exposed directly to the agent0.99
- Guiding the agent to scan and fix any agent-introduced issues0.99
- snyk1.00
- A0.99
- $10.68
- 米0.98
- TRACK 5·JUNE 30,20260.98
- Security1.00
- World'sFair1.00
-
- AlEngineer0.99
- =id.g3ef6687504_4_54#slide=id.g3ef66d87504_4_540.98
- ②☆0.73
- 00.79
- World's Fair0.97
- Snyk Packa0.94
- Checking:0.99
- Overall: He0.93
- Security1.00
- Dequirement0.97
- - THE ORIGINAL FRAME0.98
- Secure what agents generate.0.99
- 301.00
- A1.00
- $10.85
- 米0.99
- TRACK 5· JUNE 30, 20260.96
- Security1.00
- World's Fair0.96
-
- AlEngineer0.98
- g3ef66d87504_4_129#slide=id.g3ef66d87504_4_1291.00
- World's Fair0.93
- Snyk Packa0.88
- Checking:1.00
- Overalt: He0.87
- Real examples1.00
- from the last year.1.00
- snyk1.00
- A0.99
- $10.67
- 米0.99
- TRACK 5· JUNE 30, 20260.96
- Security1.00
- World'sFair1.00
-
- AlEngineer1.00
- docs.google.com/presentatlon/d/1IS752ccB1da41U2KUh70I7OtnAaloLY674TamatoVY/edit?slide=id.g3f2b99986b1_0_0#slide=id.g3f2b99986b1_0_00.96
- Ask Google0.96
- ☆0.93
- 00.82
- World'sFair0.97
- Snyk Packo0.95
- Checking:1.00
- Overalt: He0.91
- Security1.00
- APRIL 25, 20260.95
- POCKETOS / RAILWAY / CLAUDE OPUS 4.60.98
- Requirement a0.93
- Requirement1.00
- 9 seconds.0.97
- To delete an entire production database — and all backups.0.99
- "NEVER F***ING GUESS!"0.99
- The agent, quoting its own violated system prompt rule back to the enginering team. In writing.0.99
- snyk1.00
- A1.00
- $I0.68
- 米0.99
- TRACK 5·JUNE 30,20260.98
- Security1.00
- World's Fair0.97
-
- AlEngineer0.98
- docs.google.com/presentation/d/1S752ccB1daiIU2KUh70I7OtnAaloLY674TamatoVY/edit?slide=id.g3ef66d87504_4_160#slide=id.g3ef66d87504_4_1600.97
- ②☆0.67
- 00.82
- World'sFair1.00
- Snyk Packa0.96
- Checking:1.00
- Overalt: He0.90
- - GITHUB · MAY 20260.96
- The toolchain was the attack surface.0.99
- ~3,800 GitHub internalrepo exfilttrated0.95
- Trojanized VS Code extension1.00
- snyk1.00
- A0.99
- $I0.67
- 米0.99
- TRACK 5 · JUNE 30, 20260.94
- Security1.00
- World'sFair1.00
-
- AlEngineer1.00
- n/d/1IS752ccB1da41U2KUh70I7OtnAaloLY674TamatoVY/edit?slide=id.g3ef66d87504_4_223#slide=id.g3ef66d87504_4_2230.97
- ②☆0.65
- 00.83
- World'sFair1.00
- AGENTIC DEVELOPMENT SECURITY1.00
- Snyk Packo0.93
- Checking:0.99
- Secure what agents use, do, and generate.0.98
- Overalt: He0.92
- Security1.00
- NHAT AGENITS GENERATE0.94
- MHAT AGENTS USE0.94
- WHAT AGENTS DO0.99
- Ensure Trusted Output1.00
- Secure Agent Supply Chain1.00
- Govern Agent Behavior0.98
- Secure Al-generated code at the moment of0.99
- Discover and govern MCP servers, skills, and0.99
- Enforce policy inside the execution loop — before0.98
- creation.1.00
- tools before they enter agent workflows.0.99
- actions complete.1.00
- snyk1.00
- A0.99
- $10.68
- 米0.99
- TRACK 5· JUNE 30,20260.95
- Security1.00
- World'sFair1.00
-
- AlEngineer0.99
- ☆1.00
- 00.80
- World's Fair0.97
- ENSURE TRUSTED OUTPUT1.00
- NOW1.00
- Snyk Packo0.93
- Checking:0.99
- Now: Local CLl + Async hooks.0.97
- Overalt: He0.92
- Security0.99
- PRESENTED BY1.00
- Deterministic1.00
- Async — minimal latency1.00
- Minimal context consumption1.00
- Invoked every time.1.00
- Fires off the critical path on tool calls..0.99
- Only newly-introduced issues passed to agent.0.98
- Microsoft1.00
- snyk1.00
- A1.00
- $10.67
- 米0.99
- TRACK 5· JUNE 30, 20260.95
- Security1.00
- World's Fair0.96
-
- AlEngineer0.99
- docs.google.com/presentation/d/1IS752ccB1da4lU2KUh7OI7OtnAaloLY674TamatoVY/edit?slide=id.g3efcae9d5c8_0_40#slide=id.g3efcae9d5c8_0_400.98
- Ask Google0.89
- 00.84
- World's Fair0.99
- Snyk Packa0.94
- Checking:0.99
- Toxic Skill Analysis0.98
- Q1 2026 - SNYK REPORT0.97
- SKILLS ON CLAWHUB1.00
- Overalt: He0.95
- Security1.00
- Handing a0.92
- Package ecosystems (2015-2020)1.00
- Agent Skills (2026)1.00
- Requirement1.00
- Requirement a0.92
- Typosquatting attacks1.00
- ✓ Observed0.96
- 13.4%1.00
- Requirement d0.95
- J To u0.82
- Malicious maintainers1.00
- ✓ Observed0.93
- of skills audited on ClawHub have a critical issue0.99
- Post-install scripts as an attack vector1.00
- ✓ Skill 'setup" instructions0.92
- 761.00
- confirmed malicious payloads0.99
- LIME TO THE FULL ANALYSIS0.98
- snyk1.00
- A0.99
- $10.72
- 米0.99
- TRACK 5·JUNE 30,20260.98
- Security1.00
- World'sFair1.00
-
- AlEngineer1.00
- ②☆0.65
- World's Fair1.00
- Q2 2026 - SNYK REPORT - DATA FROM -10K DEVELOPERS0.98
- Snyk Packo0.93
- Checking:1.00
- Inside the Agentic Development Supply Chain0.99
- Overall: He0.92
- Security1.00
- 50.8%1.00
- 22.8%1.00
- of developers already have active MCP configurations0.98
- of developers have skills installed — averaging 18 each0.99
- 1 in 120.99
- developers with an MCP server have a high or critical finding1.00
- LINK TO THE FULL REPORT0.97
- snyk1.00
- A0.99
- $10.70
- 米0.99
- TRACK 5· JUNE 30,20260.97
- Security1.00
- World's Fair0.97
Transcript
295 cues· 4,681 words· 25,649 chars
- 0:13 I'm a product director here at Snyk and gonna be talking to you about agentic development security and specifically talking about how we can gain confidence when we use agents, especially as we give them more autonomy.
- 0:23 It's a very common theme I've heard in this track and a number of the other tracks today.
- 0:30 I'm not gonna go through the full history of LLMs, but the model context protocol release was a really big moment.
- 0:35 Until then, I don't know what you guys are doing, but I was very often copying and pasting between
- 0:41 agentic clients and some other services.
- 0:42 And with MCP, I think people really started to connect this and have a much more really connected AI system.
- 0:48 And I'm not saying that MCP is the end all be all, and I may or may not have been amongst the people who were saying that MCP would die at some point last year, but it has been a game changer in the sense that developers started to connect agents to external tools and services.
- 1:04 And at that time, there really wasn't any security to speak of.
- 1:08 Like most companies, we released an MCP server almost immediately.
- 1:14 Ours specifically enabled local directories to be scanned by our security scanning engines.
- 1:19 Developers could ask questions in natural language about the security issues that were identified.
- 1:24 They could learn why specific vulnerabilities were important or how they might be exploited and then work iteratively towards a fix.
- 1:31 Shortly thereafter, we decided to pair our MCP server with rules, and the rules basically ensured that any AI-generated code would be tested, and if there were security issues identified, that they would be automatically fixed.
- 1:44 It was simple, it was fast to deploy, and it did solve a meaningful pain point for our customers.
- 1:49 So that really was our original position, secure agent-generated code at the moment of inception.
- 1:56 But over the last year, we learned that this framing was really incomplete.
- 2:00 Our customers started telling us that they were not only worried about the code that was being generated, they were also worried about what the agent had access to, and then also the actions the agent might be taking.
- 2:11 So I'm gonna just mention briefly a few incidents that have come up over the last year or so.
- 2:16 I think we've talked about them in the keynote that Manoj gave earlier today, but also I think we've seen some of these in other presentations.
- 2:23 But just as a quick refresher, about a year ago, we saw a Replitz agent ignore a code freeze instruction and ultimately deleted a production database.
- 2:34 It tried to cover up that it did this, fabricated records to basically say like, no, there was no issue whatsoever.
- 2:40 And finally, it said that there was no way to recover.
- 2:42 Fortunately, it turned out that that was wrong.
- 2:44 They were able to recover, but the damage was still done.
- 2:48 Then in April, I know we talked about this just a couple hours ago, but there was the Pocket OS incident.
- 2:53 An agent, again, found an overprivileged API token, and that resulted in a production database being deleted.
- 3:01 The backups were also deleted, and so a three-month-old backup is what could be used to ultimately try to get back to recovery.
- 3:09 What's really interesting here is that the agent wasn't acting maliciously.
- 3:12 It was actually trying to solve a problem.
- 3:14 It was trying to solve
- 3:15 perceived to be a credential mismatch, but there was nothing in place to stop it.
- 3:20 Those two examples were really about the agent actions that might be taken, but that's not always the case.
- 3:24 That's not always what the attack surface is.
- 3:27 Just last month, Team PCP was able to exfiltrate almost 4,000 of GitHub's internal repositories using malicious VS Code extension.
- 3:37 So all of this and kind of us being in the security space for the last 10 years and talking to our customers, it's really shaped how we think about agentic development security and what that really means.
- 3:49 And our belief is that in order to confidently use agents for software development at scale and to start letting them operate more autonomously in long-running tasks, whether it's just getting up to make a cup of coffee or letting them run overnight,
- 4:02 It's really critical to secure what agents generate, what they use, and what they do.
- 4:07 And I'll spend a couple minutes talking about our journey in each of these pillars over the last year, what we've learned, and our current perspective.
- 4:16 As I mentioned at the top, this has been our longest area of experimentation and investment.
- 4:21 It's securing the code that the agents generate.
- 4:24 And the reason for that is we don't want issues to make it to production.
- 4:27 We don't want to kind of increase that backlog, which has been so challenging to manage and is now a luxury that companies just cannot afford.
- 4:35 Most companies do have security checks in their deployment pipelines.
- 4:39 And so even if they don't make it to production, we want to ensure that bottlenecks are not getting created at those stages.
- 4:45 I mentioned our original approach, MCP server plus rules.
- 4:49 It was really easy to paste an MCP configuration and a rule definition.
- 4:55 And over time, we added shortcuts to make that even easier.
- 4:58 And the agent clients actually made it like simple commands to enable these configurations through plugins or just simple CLI tools.
- 5:06 But the approach did have real limitations.
- 5:08 Agents sometimes ignored the rule files.
loading
Chapters
- 0:00 Gaining confidence as agents gain autonomy
- 0:36 How MCP connected agents to tools
- 1:14 Snyk's first answer: an MCP server plus rules
- 2:03 Why securing generated code was only half the problem
- 2:29 Three incidents: Replit, Pocket OS, and GitHub
- 3:46 The three pillars: what agents generate, use, and do
- 4:11 Pillar one: securing what agents generate
- 5:26 From ignored rule files to async Python hooks
- 6:40 Pillar two: the agent supply chain and skill risk
- 7:33 Auto discovering the AI components on your machine
- 8:11 Adoption data: who is running MCP servers and skills
- 9:27 Pillar three: governing agent behavior
- 11:20 Handing off to a live demo
- 13:29 Dan Arpino's local security pair programmer
- 14:56 Visibility into every LLM, MCP server, and skill
- 15:47 Per project guardrails and auto fixing
- 18:34 Blocking an agent from reading your secrets
- 20:17 Security teams versus developers
- 21:33 Q&A: false positives, local vs cloud, and remediation