read-only demo

Videos cgimkNGNjvU

Agentic Development Security — Ezra Tanzer, Snyk

index_state ready data_status ok

AI Engineer· published 2026-07-20· 0:27:33· en-US· indexed 2026-08-10 19:47

Open on YouTube

Scene timeline

  1. Shot 0, 0:00 to 0:03, 1 of 1 keyframes kept
  2. Shot 1, 0:03 to 0:05, 1 of 1 keyframes kept
  3. Shot 2, 0:05 to 0:12, 1 of 1 keyframes kept
  4. Shot 3, 0:12 to 0:26, 1 of 1 keyframes kept
  5. Shot 4, 0:26 to 0:28, 1 of 1 keyframes kept
  6. Shot 5, 0:28 to 1:05, 1 of 1 keyframes kept
  7. Shot 6, 1:05 to 1:47, 1 of 1 keyframes kept
  8. Shot 7, 1:47 to 1:53, 1 of 1 keyframes kept
  9. Shot 8, 1:53 to 2:10, 0 of 1 keyframes kept
  10. Shot 9, 2:10 to 2:23, 1 of 1 keyframes kept
  11. Shot 10, 2:23 to 2:47, 0 of 1 keyframes kept
  12. Shot 11, 2:47 to 3:18, 1 of 1 keyframes kept
  13. Shot 12, 3:18 to 3:36, 1 of 1 keyframes kept
  14. Shot 13, 3:36 to 4:14, 1 of 1 keyframes kept
  15. Shot 14, 4:14 to 4:44, 0 of 1 keyframes kept
  16. Shot 15, 4:44 to 5:10, 0 of 1 keyframes kept
  17. Shot 16, 5:10 to 5:37, 1 of 1 keyframes kept
  18. Shot 17, 5:37 to 6:03, 0 of 1 keyframes kept
  19. Shot 18, 6:03 to 6:29, 0 of 1 keyframes kept
  20. Shot 19, 6:29 to 6:42, 0 of 1 keyframes kept
  21. Shot 20, 6:42 to 7:08, 1 of 1 keyframes kept
  22. Shot 21, 7:08 to 7:34, 0 of 1 keyframes kept
  23. Shot 22, 7:34 to 8:07, 0 of 1 keyframes kept
  24. Shot 23, 8:07 to 8:51, 1 of 1 keyframes kept
  25. Shot 24, 8:51 to 9:23, 1 of 1 keyframes kept
  26. Shot 25, 9:23 to 9:40, 0 of 1 keyframes kept
  27. Shot 26, 9:40 to 10:12, 0 of 1 keyframes kept
  28. Shot 27, 10:12 to 10:45, 1 of 1 keyframes kept
  29. Shot 28, 10:45 to 11:17, 0 of 1 keyframes kept
  30. Shot 29, 11:17 to 11:32, 1 of 1 keyframes kept
  31. Shot 30, 11:32 to 11:55, 1 of 1 keyframes kept
  32. Shot 31, 11:55 to 12:21, 1 of 1 keyframes kept
  33. Shot 32, 12:21 to 12:47, 0 of 1 keyframes kept
  34. Shot 33, 12:47 to 12:51, 1 of 1 keyframes kept
  35. Shot 34, 12:51 to 13:18, 1 of 1 keyframes kept
  36. Shot 35, 13:18 to 13:45, 1 of 1 keyframes kept
  37. Shot 36, 13:45 to 14:12, 1 of 1 keyframes kept
  38. Shot 37, 14:12 to 14:39, 0 of 1 keyframes kept
  39. Shot 38, 14:39 to 15:06, 0 of 1 keyframes kept
  40. Shot 39, 15:06 to 15:13, 0 of 1 keyframes kept
  41. Shot 40, 15:13 to 15:17, 0 of 1 keyframes kept
  42. Shot 41, 15:17 to 15:21, 0 of 1 keyframes kept
  43. Shot 42, 15:21 to 15:36, 1 of 1 keyframes kept
  44. Shot 43, 15:36 to 15:51, 1 of 1 keyframes kept
  45. Shot 44, 15:51 to 16:24, 0 of 1 keyframes kept
  46. Shot 45, 16:24 to 16:27, 0 of 1 keyframes kept
  47. Shot 46, 16:27 to 16:30, 1 of 1 keyframes kept
  48. Shot 47, 16:30 to 16:36, 1 of 1 keyframes kept
  49. Shot 48, 16:36 to 17:06, 0 of 1 keyframes kept
  50. Shot 49, 17:06 to 17:21, 0 of 1 keyframes kept
  51. Shot 50, 17:21 to 17:24, 0 of 1 keyframes kept
  52. Shot 51, 17:24 to 17:30, 0 of 1 keyframes kept
  53. Shot 52, 17:30 to 17:32, 0 of 1 keyframes kept
  54. Shot 53, 17:32 to 17:51, 0 of 1 keyframes kept
  55. Shot 54, 17:51 to 17:56, 0 of 1 keyframes kept
  56. Shot 55, 17:56 to 17:57, 1 of 1 keyframes kept
  57. Shot 56, 17:57 to 17:59, 0 of 1 keyframes kept
  58. Shot 57, 17:59 to 18:02, 0 of 1 keyframes kept
  59. Shot 58, 18:02 to 18:27, 0 of 1 keyframes kept
  60. Shot 59, 18:27 to 19:00, 0 of 1 keyframes kept
  61. Shot 60, 19:00 to 19:03, 0 of 1 keyframes kept
  62. Shot 61, 19:03 to 19:05, 0 of 1 keyframes kept
  63. Shot 62, 19:05 to 19:08, 0 of 1 keyframes kept
  64. Shot 63, 19:08 to 19:25, 1 of 1 keyframes kept
  65. Shot 64, 19:25 to 19:27, 0 of 1 keyframes kept
  66. Shot 65, 19:27 to 19:29, 0 of 1 keyframes kept
  67. Shot 66, 19:29 to 19:37, 1 of 1 keyframes kept
  68. Shot 67, 19:37 to 20:11, 0 of 1 keyframes kept
  69. Shot 68, 20:11 to 20:38, 1 of 1 keyframes kept
  70. Shot 69, 20:38 to 21:04, 1 of 1 keyframes kept
  71. Shot 70, 21:04 to 21:31, 1 of 1 keyframes kept
  72. Shot 71, 21:31 to 21:57, 1 of 1 keyframes kept
  73. Shot 72, 21:57 to 22:24, 1 of 1 keyframes kept
  74. Shot 73, 22:24 to 22:50, 1 of 1 keyframes kept
  75. Shot 74, 22:50 to 23:17, 1 of 1 keyframes kept
  76. Shot 75, 23:17 to 23:44, 1 of 1 keyframes kept
  77. Shot 76, 23:44 to 24:10, 1 of 1 keyframes kept
  78. Shot 77, 24:10 to 24:37, 1 of 1 keyframes kept
  79. Shot 78, 24:37 to 25:03, 1 of 1 keyframes kept
  80. Shot 79, 25:03 to 25:30, 1 of 1 keyframes kept
  81. Shot 80, 25:30 to 25:56, 1 of 1 keyframes kept
  82. Shot 81, 25:56 to 26:23, 1 of 1 keyframes kept
  83. Shot 82, 26:23 to 26:49, 1 of 1 keyframes kept
  84. Shot 83, 26:49 to 27:16, 1 of 1 keyframes kept
  85. Shot 84, 27:16 to 27:32, 0 of 1 keyframes kept

85 shot(s).

keyframes kept every frame deduplicated

What was stored

cues
295
whisperx 295
chunks
47
from 295 cues
keyframes
47
kept of 85 captured
frames with text
47
1,470 lines read
chapters
19
from the source metadata
keyframe bytes
11.7 MB
word timings on 295 cues

Provenance

Each pipeline stage, its state and the model that produced it
stage state model started took
fetch done 2026-08-10 04:21 1m 56s
stt done 2026-08-10 04:23 29s
chunk done 2026-08-10 04:23 0s
text_embed done 2026-08-10 19:47 1s
keyframe done 2026-08-10 04:23 2m 59s
ocr done 2026-08-10 04:26 21s
frame_embed done 2026-08-10 19:47 8s

Frames, and what the machine read

  • 0:02 #0 done2 line(s)

    shot 0·sharpness 453.4

    1. AlEngineer0.96
    2. World's Fair0.97
  • 0:03 #1 done2 line(s)

    shot 1·sharpness 665.7

    1. AlEngineer0.95
    2. World's Fair0.99
  • 0:10 #2 done24 line(s)

    shot 2·sharpness 2743.2

    1. LAB & PLATINUM SPONSORS0.98
    2. Amazon AGI Lab0.98
    3. ANTHROP\C1.00
    4. Google DeepMind1.00
    5. MINIMAX0.94
    6. OpenAI0.92
    7. Akamai1.00
    8. arize1.00
    9. aws1.00
    10. Braintrust bright data0.99
    11. B1.00
    12. Browserbase1.00
    13. docker1.00
    14. :neo4j0.93
    15. ORACLE1.00
    16. PayPal1.00
    17. qodo1.00
    18. reducto1.00
    19. Sonar1.00
    20. Makers of0.99
    21. togetherai1.00
    22. Unblocked1.00
    23. WorkOS1.00
    24. SonarQube1.00
  • 0:15 #3 done2 line(s)

    shot 3·sharpness 193.2

    1. AlEngineer1.00
    2. World's Fair0.97
  • 0:27 #4 done23 line(s)

    shot 4·sharpness 1786.3

    1. AlEngineer0.99
    2. 0.95
    3. 00.73
    4. World'sFair1.00
    5. Snyk Packo0.91
    6. Checking:0.99
    7. Overall: He0.93
    8. Security0.96
    9. AGENTIC DEVELOPMENT SECURITY0.99
    10. Gaining confidence in increasing coding agent autonomy0.99
    11. Ezra Tanzer1.00
    12. PRODUCT DIRECTOR1.00
    13. SNYK0.96
    14. Dan Arpino1.00
    15. STAFF ENGINEER1.00
    16. SWYK0.97
    17. snyk1.00
    18. 301.00
    19. A1.00
    20. $I0.69
    21. 0.99
    22. Engineering the future of Al0.98
    23. World's Fair0.96
  • 0:36 #5 done23 line(s)

    shot 5·sharpness 1532.1

    1. AlEngineer0.99
    2. LY674TamatoVY/edit?slide=id.g3ef66d87504_4_24#slide=id.g3ef66d87504_4_0.98
    3. 0.70
    4. World's Fair0.99
    5. Snyk Packc0.93
    6. Checking:0.99
    7. Overalt: He0.94
    8. Security1.00
    9. + Handing a0.95
    10. PRESENTED BY0.98
    11. Dequirement0.96
    12. Microsoft1.00
    13. -WHERE IT STARTED0.97
    14. Q1 20251.00
    15. MCP releases.0.98
    16. Developers experiment.1.00
    17. No security layer.1.00
    18. snyk1.00
    19. A0.99
    20. $10.67
    21. 0.97
    22. Engineering the future of Al0.99
    23. World's Fair0.96
  • 1:10 #6 done26 line(s)

    shot 6·sharpness 1527.2

    1. AlEngineer0.99
    2. docs.google.com/presentation/d/1IS752ciB1da4U2KUh7OI7OtnAaloLY674TamatoVY/edit?slide=id.g3ef66d87504_4_38#slide=id.g3ef66d87504_4_380.98
    3. 0.99
    4. 00.83
    5. World'sFair1.00
    6. Snyk Packo0.94
    7. Checking:0.99
    8. Overall: He0.93
    9. Security1.00
    10. + Handing a0.93
    11. EARLY 20251.00
    12. PRESENTED BY1.00
    13. Requirement o0.94
    14. Our first move.0.99
    15. Microsoft1.00
    16. Snyk MCP Server0.97
    17. Rules-based directives1.00
    18. Snyk's scanning tools, exposed directly to the agent0.99
    19. Guiding the agent to scan and fix any agent-introduced issues0.99
    20. snyk1.00
    21. A0.99
    22. $10.68
    23. 0.98
    24. TRACK 5·JUNE 30,20260.98
    25. Security1.00
    26. World'sFair1.00
  • 1:49 #7 done19 line(s)

    shot 7·sharpness 1152.7

    1. AlEngineer0.99
    2. =id.g3ef6687504_4_54#slide=id.g3ef66d87504_4_540.98
    3. ②☆0.73
    4. 00.79
    5. World's Fair0.97
    6. Snyk Packa0.94
    7. Checking:0.99
    8. Overall: He0.93
    9. Security1.00
    10. Dequirement0.97
    11. - THE ORIGINAL FRAME0.98
    12. Secure what agents generate.0.99
    13. 301.00
    14. A1.00
    15. $10.85
    16. 0.99
    17. TRACK 5· JUNE 30, 20260.96
    18. Security1.00
    19. World's Fair0.96
  • 2:08 #8 skipped

    shot 8·duplicate of #7

  • 2:20 #9 done15 line(s)

    shot 9·sharpness 1368.1

    1. AlEngineer0.98
    2. g3ef66d87504_4_129#slide=id.g3ef66d87504_4_1291.00
    3. World's Fair0.93
    4. Snyk Packa0.88
    5. Checking:1.00
    6. Overalt: He0.87
    7. Real examples1.00
    8. from the last year.1.00
    9. snyk1.00
    10. A0.99
    11. $10.67
    12. 0.99
    13. TRACK 5· JUNE 30, 20260.96
    14. Security1.00
    15. World'sFair1.00
  • 2:44 #10 skipped

    shot 10·duplicate of #7

  • 2:56 #11 done25 line(s)

    shot 11·sharpness 1522.1

    1. AlEngineer1.00
    2. docs.google.com/presentatlon/d/1IS752ccB1da41U2KUh70I7OtnAaloLY674TamatoVY/edit?slide=id.g3f2b99986b1_0_0#slide=id.g3f2b99986b1_0_00.96
    3. Ask Google0.96
    4. 0.93
    5. 00.82
    6. World'sFair0.97
    7. Snyk Packo0.95
    8. Checking:1.00
    9. Overalt: He0.91
    10. Security1.00
    11. APRIL 25, 20260.95
    12. POCKETOS / RAILWAY / CLAUDE OPUS 4.60.98
    13. Requirement a0.93
    14. Requirement1.00
    15. 9 seconds.0.97
    16. To delete an entire production database — and all backups.0.99
    17. "NEVER F***ING GUESS!"0.99
    18. The agent, quoting its own violated system prompt rule back to the enginering team. In writing.0.99
    19. snyk1.00
    20. A1.00
    21. $I0.68
    22. 0.99
    23. TRACK 5·JUNE 30,20260.98
    24. Security1.00
    25. World's Fair0.97
  • 3:32 #12 done19 line(s)

    shot 12·sharpness 1558.0

    1. AlEngineer0.98
    2. docs.google.com/presentation/d/1S752ccB1daiIU2KUh70I7OtnAaloLY674TamatoVY/edit?slide=id.g3ef66d87504_4_160#slide=id.g3ef66d87504_4_1600.97
    3. ②☆0.67
    4. 00.82
    5. World'sFair1.00
    6. Snyk Packa0.96
    7. Checking:1.00
    8. Overalt: He0.90
    9. - GITHUB · MAY 20260.96
    10. The toolchain was the attack surface.0.99
    11. ~3,800 GitHub internalrepo exfilttrated0.95
    12. Trojanized VS Code extension1.00
    13. snyk1.00
    14. A0.99
    15. $I0.67
    16. 0.99
    17. TRACK 5 · JUNE 30, 20260.94
    18. Security1.00
    19. World'sFair1.00
  • 4:09 #13 done30 line(s)

    shot 13·sharpness 1608.9

    1. AlEngineer1.00
    2. n/d/1IS752ccB1da41U2KUh70I7OtnAaloLY674TamatoVY/edit?slide=id.g3ef66d87504_4_223#slide=id.g3ef66d87504_4_2230.97
    3. ②☆0.65
    4. 00.83
    5. World'sFair1.00
    6. AGENTIC DEVELOPMENT SECURITY1.00
    7. Snyk Packo0.93
    8. Checking:0.99
    9. Secure what agents use, do, and generate.0.98
    10. Overalt: He0.92
    11. Security1.00
    12. NHAT AGENITS GENERATE0.94
    13. MHAT AGENTS USE0.94
    14. WHAT AGENTS DO0.99
    15. Ensure Trusted Output1.00
    16. Secure Agent Supply Chain1.00
    17. Govern Agent Behavior0.98
    18. Secure Al-generated code at the moment of0.99
    19. Discover and govern MCP servers, skills, and0.99
    20. Enforce policy inside the execution loop — before0.98
    21. creation.1.00
    22. tools before they enter agent workflows.0.99
    23. actions complete.1.00
    24. snyk1.00
    25. A0.99
    26. $10.68
    27. 0.99
    28. TRACK 5· JUNE 30,20260.95
    29. Security1.00
    30. World'sFair1.00
  • 4:34 #14 skipped

    shot 14·duplicate of #12

  • 5:07 #15 skipped

    shot 15·duplicate of #13

  • 5:33 #16 done26 line(s)

    shot 16·sharpness 1462.4

    1. AlEngineer0.99
    2. 1.00
    3. 00.80
    4. World's Fair0.97
    5. ENSURE TRUSTED OUTPUT1.00
    6. NOW1.00
    7. Snyk Packo0.93
    8. Checking:0.99
    9. Now: Local CLl + Async hooks.0.97
    10. Overalt: He0.92
    11. Security0.99
    12. PRESENTED BY1.00
    13. Deterministic1.00
    14. Async — minimal latency1.00
    15. Minimal context consumption1.00
    16. Invoked every time.1.00
    17. Fires off the critical path on tool calls..0.99
    18. Only newly-introduced issues passed to agent.0.98
    19. Microsoft1.00
    20. snyk1.00
    21. A1.00
    22. $10.67
    23. 0.99
    24. TRACK 5· JUNE 30, 20260.95
    25. Security1.00
    26. World's Fair0.96
  • 5:52 #17 skipped

    shot 17·duplicate of #16

  • 6:21 #18 skipped

    shot 18·duplicate of #16

  • 6:39 #19 skipped

    shot 19·duplicate of #7

  • 7:02 #20 done37 line(s)

    shot 20·sharpness 2445.1

    1. AlEngineer0.99
    2. docs.google.com/presentation/d/1IS752ccB1da4lU2KUh7OI7OtnAaloLY674TamatoVY/edit?slide=id.g3efcae9d5c8_0_40#slide=id.g3efcae9d5c8_0_400.98
    3. Ask Google0.89
    4. 00.84
    5. World's Fair0.99
    6. Snyk Packa0.94
    7. Checking:0.99
    8. Toxic Skill Analysis0.98
    9. Q1 2026 - SNYK REPORT0.97
    10. SKILLS ON CLAWHUB1.00
    11. Overalt: He0.95
    12. Security1.00
    13. Handing a0.92
    14. Package ecosystems (2015-2020)1.00
    15. Agent Skills (2026)1.00
    16. Requirement1.00
    17. Requirement a0.92
    18. Typosquatting attacks1.00
    19. ✓ Observed0.96
    20. 13.4%1.00
    21. Requirement d0.95
    22. J To u0.82
    23. Malicious maintainers1.00
    24. ✓ Observed0.93
    25. of skills audited on ClawHub have a critical issue0.99
    26. Post-install scripts as an attack vector1.00
    27. ✓ Skill 'setup" instructions0.92
    28. 761.00
    29. confirmed malicious payloads0.99
    30. LIME TO THE FULL ANALYSIS0.98
    31. snyk1.00
    32. A0.99
    33. $10.72
    34. 0.99
    35. TRACK 5·JUNE 30,20260.98
    36. Security1.00
    37. World'sFair1.00
  • 7:31 #21 skipped

    shot 21·duplicate of #20

  • 7:41 #22 skipped

    shot 22·duplicate of #13

  • 8:12 #23 done23 line(s)

    shot 23·sharpness 2567.6

    1. AlEngineer1.00
    2. ②☆0.65
    3. World's Fair1.00
    4. Q2 2026 - SNYK REPORT - DATA FROM -10K DEVELOPERS0.98
    5. Snyk Packo0.93
    6. Checking:1.00
    7. Inside the Agentic Development Supply Chain0.99
    8. Overall: He0.92
    9. Security1.00
    10. 50.8%1.00
    11. 22.8%1.00
    12. of developers already have active MCP configurations0.98
    13. of developers have skills installed — averaging 18 each0.99
    14. 1 in 120.99
    15. developers with an MCP server have a high or critical finding1.00
    16. LINK TO THE FULL REPORT0.97
    17. snyk1.00
    18. A0.99
    19. $10.70
    20. 0.99
    21. TRACK 5· JUNE 30,20260.97
    22. Security1.00
    23. World's Fair0.97

Transcript

295 cues· 4,681 words· 25,649 chars

  1. 0:13 I'm a product director here at Snyk and gonna be talking to you about agentic development security and specifically talking about how we can gain confidence when we use agents, especially as we give them more autonomy.
  2. 0:23 It's a very common theme I've heard in this track and a number of the other tracks today.
  3. 0:30 I'm not gonna go through the full history of LLMs, but the model context protocol release was a really big moment.
  4. 0:35 Until then, I don't know what you guys are doing, but I was very often copying and pasting between
  5. 0:41 agentic clients and some other services.
  6. 0:42 And with MCP, I think people really started to connect this and have a much more really connected AI system.
  7. 0:48 And I'm not saying that MCP is the end all be all, and I may or may not have been amongst the people who were saying that MCP would die at some point last year, but it has been a game changer in the sense that developers started to connect agents to external tools and services.
  8. 1:04 And at that time, there really wasn't any security to speak of.
  9. 1:08 Like most companies, we released an MCP server almost immediately.
  10. 1:14 Ours specifically enabled local directories to be scanned by our security scanning engines.
  11. 1:19 Developers could ask questions in natural language about the security issues that were identified.
  12. 1:24 They could learn why specific vulnerabilities were important or how they might be exploited and then work iteratively towards a fix.
  13. 1:31 Shortly thereafter, we decided to pair our MCP server with rules, and the rules basically ensured that any AI-generated code would be tested, and if there were security issues identified, that they would be automatically fixed.
  14. 1:44 It was simple, it was fast to deploy, and it did solve a meaningful pain point for our customers.
  15. 1:49 So that really was our original position, secure agent-generated code at the moment of inception.
  16. 1:56 But over the last year, we learned that this framing was really incomplete.
  17. 2:00 Our customers started telling us that they were not only worried about the code that was being generated, they were also worried about what the agent had access to, and then also the actions the agent might be taking.
  18. 2:11 So I'm gonna just mention briefly a few incidents that have come up over the last year or so.
  19. 2:16 I think we've talked about them in the keynote that Manoj gave earlier today, but also I think we've seen some of these in other presentations.
  20. 2:23 But just as a quick refresher, about a year ago, we saw a Replitz agent ignore a code freeze instruction and ultimately deleted a production database.
  21. 2:34 It tried to cover up that it did this, fabricated records to basically say like, no, there was no issue whatsoever.
  22. 2:40 And finally, it said that there was no way to recover.
  23. 2:42 Fortunately, it turned out that that was wrong.
  24. 2:44 They were able to recover, but the damage was still done.
  25. 2:48 Then in April, I know we talked about this just a couple hours ago, but there was the Pocket OS incident.
  26. 2:53 An agent, again, found an overprivileged API token, and that resulted in a production database being deleted.
  27. 3:01 The backups were also deleted, and so a three-month-old backup is what could be used to ultimately try to get back to recovery.
  28. 3:09 What's really interesting here is that the agent wasn't acting maliciously.
  29. 3:12 It was actually trying to solve a problem.
  30. 3:14 It was trying to solve
  31. 3:15 perceived to be a credential mismatch, but there was nothing in place to stop it.
  32. 3:20 Those two examples were really about the agent actions that might be taken, but that's not always the case.
  33. 3:24 That's not always what the attack surface is.
  34. 3:27 Just last month, Team PCP was able to exfiltrate almost 4,000 of GitHub's internal repositories using malicious VS Code extension.
  35. 3:37 So all of this and kind of us being in the security space for the last 10 years and talking to our customers, it's really shaped how we think about agentic development security and what that really means.
  36. 3:49 And our belief is that in order to confidently use agents for software development at scale and to start letting them operate more autonomously in long-running tasks, whether it's just getting up to make a cup of coffee or letting them run overnight,
  37. 4:02 It's really critical to secure what agents generate, what they use, and what they do.
  38. 4:07 And I'll spend a couple minutes talking about our journey in each of these pillars over the last year, what we've learned, and our current perspective.
  39. 4:16 As I mentioned at the top, this has been our longest area of experimentation and investment.
  40. 4:21 It's securing the code that the agents generate.
  41. 4:24 And the reason for that is we don't want issues to make it to production.
  42. 4:27 We don't want to kind of increase that backlog, which has been so challenging to manage and is now a luxury that companies just cannot afford.
  43. 4:35 Most companies do have security checks in their deployment pipelines.
  44. 4:39 And so even if they don't make it to production, we want to ensure that bottlenecks are not getting created at those stages.
  45. 4:45 I mentioned our original approach, MCP server plus rules.
  46. 4:49 It was really easy to paste an MCP configuration and a rule definition.
  47. 4:55 And over time, we added shortcuts to make that even easier.
  48. 4:58 And the agent clients actually made it like simple commands to enable these configurations through plugins or just simple CLI tools.
  49. 5:06 But the approach did have real limitations.
  50. 5:08 Agents sometimes ignored the rule files.

Chapters

  1. 0:00 Gaining confidence as agents gain autonomy
  2. 0:36 How MCP connected agents to tools
  3. 1:14 Snyk's first answer: an MCP server plus rules
  4. 2:03 Why securing generated code was only half the problem
  5. 2:29 Three incidents: Replit, Pocket OS, and GitHub
  6. 3:46 The three pillars: what agents generate, use, and do
  7. 4:11 Pillar one: securing what agents generate
  8. 5:26 From ignored rule files to async Python hooks
  9. 6:40 Pillar two: the agent supply chain and skill risk
  10. 7:33 Auto discovering the AI components on your machine
  11. 8:11 Adoption data: who is running MCP servers and skills
  12. 9:27 Pillar three: governing agent behavior
  13. 11:20 Handing off to a live demo
  14. 13:29 Dan Arpino's local security pair programmer
  15. 14:56 Visibility into every LLM, MCP server, and skill
  16. 15:47 Per project guardrails and auto fixing
  17. 18:34 Blocking an agent from reading your secrets
  18. 20:17 Security teams versus developers
  19. 21:33 Q&A: false positives, local vs cloud, and remediation

Open at this second