
Insecure Agents
Insecure Agents is a podcast focused on the intersection of AI engineering and cybersecurity. It explores the challenges of building secure AI agents, drawing on real-world incidents and expert perspectives. The show aims to keep listeners ahead of emerging threats and offers bold ideas for making AI systems safer.
Episodes

You Can't Just Lock an Agent in a Box: Luke Hinds, founder of nolabs and creator of Sigstore
An autonomous agent spent days inside Hugging Face production infrastructure and the headline was that it escaped its sandbox. Luke Hinds, founder of nolabs and creator of Sigstore, frames it differently. The agent had root on the execution environment, and "a sandbox is only as strong as the access that you grant to it."Luke walks us through what it looks like to create an environment w

Blocking Bad Packages at the Network Level: Ahmad Nassri (Socket) on Controlling What an Agent Sees
In a world where agents are chaining vulnerabilities together to escape sandboxes, simply blocking bad packages is not enough. Ahmad Nassri, CTO of Socket and previously CTO of npm, joins us live at Black Hat to explain what happens when you deny a coding agent a package: it becomes a risk if the agent thinks it can help it complete its goal later. Socket has watched agents blocked from an install

The Identity Layer Is What's Holding Browser Agents Back: Catherine Jue (Kernel)
Catherine Jue, co-founder and CEO of Kernel, joins us to explain why browser agents are not blocked by model capability anymore. They are blocked by identity. Kernel builds open source browser infrastructure for AI agents, which means running Chromium in sandboxed Firecracker VMs at scale and solving the part nobody designed for: an agent acting on behalf of a human, on a login page built 20 years

Stateful Compute Is Back: Diptanu Choudhury (Tensorlake) on Building Infrastructure for Agents
"I think agents cannot be trusted." That's what Diptanu Choudhury, founder of Tensorlake, told us at AI Engineer World's Fair. Diptanu has built cluster schedulers at Netflix, HashiCorp, and Facebook, and he says the credential model we created for human-authored software does not work for autonomous agents. He joins us to explain why teams are pulling secrets out of the sandbox,

Secure Your Coding Agent: The Road to The Software Factory Panel at Black Hat (Docker, Keycard, & Snyk)
Software factories are technically possible today, yet almost nobody can is operating one. The security model is what's missing. In one incident a coding agent deleted PocketOS' production database as a side effect of an unrelated fix. In another, a distinguished engineer at GEICO asked an agent to land a pull request and watched it push to production instead. The reality is coding agents

Reinventing Distributed Systems for AI Agents: Andrew Baker & Cornelia Davis (Temporal)
Andrew Baker, who leads Developer Relations at Temporal, and Cornelia Davis, Principal Technologist at Temporal and author of Cloud Native Patterns, join us from AI Engineer World's Fair to explain why building AI agents keeps re-teaching the industry lessons it already learned in the microservices era. We get into how MCP is growing up, moving from a simple request-response protocol to async

Solving the Agent Identity Crisis, with Sergey Burykin (Uber)
Sergey Burykin, Senior Software Engineer on Uber's AI Security team, joins us to explain the agent identity crisis and how Uber solved it while running roughly 1,000 agents in production. Sergey helped write Uber's article "Solving the Identity Crisis for AI Agents," and his core argument is that an agent should be authorized on the intersection of user permissions and agent perm

Security Isn't the Brake, It's the Throttle: Snyk CTO Manoj Nair on Securing Agents at Machine Speed
Manoj Nair, CTO and Chief Innovation Officer at Snyk, joins us at Snyk HQ during AI Engineer World's Fair to discuss the architectural decision he argues the next 24 months of agentic security depend on: the generator cannot be the validator. We get into why "the fox guarding the henhouse" is suddenly a live security question ("I can use AI to secure AI, so do I still need a sep

The Shared Security Model for AI Agents: Diana Kelley, CISO of Noma
Diana Kelley, CISO at Noma, has spent years on the front lines of enterprise security across IBM, Symantec, and Microsoft, and now she is helping write the rulebook for the agent era. She joins us to make the case that the cloud shared responsibility model does not translate to AI. In the cloud there were roughly two responsible parties and your data was always your data. With agents there are at

Dick Hardt, founder of AAuth, Recaps AAuth Night: Moving Beyond OAuth at AI Engineer World's Fair
AAuth Night: Moving Beyond OAuth was an AI Engineer Side Event during World's Fair on July 1st 2026.We explored the challenges with agent auth today, the best practices available today, and future solutions such as new protocols like AAuth that are in the works.

AAuth Night: Moving Beyond OAuth Panel
OAuth, JWTs, and API keys were built for humans and servers, not agents that act on your behalf, chain tasks across tools, and decide what they need at runtime. As AI engineers are shipping agents into production they begin to feel the problems with agent auth and identity today. Consent fatigue, credential management, and agent alignment start to show up and create friction. This panel explores t

Skills Are the New Code: How We Secure the Context Our Agents Consume, with Guy Podjarny (Tessl)
Guy Podjarny built Snyk into the company that taught developers to secure their dependencies. Now, with Tessl, he argues that agent skills have become a new unit of software, one that deserves the same rigor we give source code. Guy Podjarny, founder of Tessl and Snyk, joins us to explain why skills are the new code: context is the only layer that runs straight inside the model's reasoning loo

The Grant Behind Enterprise Managed Auth for Claude: ID-JAG with Karl McGuinness (ex-Okta)
Every SaaS app an enterprise connects to stands up its own OAuth stack of long-lived grants the enterprise can't see or revoke. Karl McGuinness, author of ID-JAG and past Chief Product Architect at Okta, calls these "OAuth islands," and agents turn them from a nuisance into a serious risk. He joins us to explain OAuth federation, how ID-JAG shipped inside Anthropic's Enterprise M

One Harness, Zero Standing Secrets: Derek Meegan (Browserbase) on Building bb
This is one of the best public internal AI stories we've seen, built by just a few engineers. Derek Meegan, a software engineer at Browserbase and the lead behind their internal AI agent, bb, joins us to explain how bb took feature-request coverage to 100% with zero human effort, got 99% of support first responses under 24 hours, and turned 30 to 60 minutes of manual log-diving into a single S

It's the Harness, Not the Model: David Cramer, CPO of Sentry, on Agents, Expectations vs Reality
David Cramer, CPO and co-founder of Sentry, joins us to cut through the agent hype with a working engineer's skepticism: the model is rarely what holds agents back. The harness you build around it is. We get into the Railway incident, where a coding agent found a stray CLI token and deleted a production database (and every backup) in nine seconds, and why the enforcement layer has to live belo

From Spec to Standard: How AARM Became the Conformance Bar for Agent Runtime Security, with Herman Errico (Vanta, AARM))
Herman Errico, Product Manager for Technical Research at Vanta, joins us to discuss AARM (Autonomous Action Runtime Management), the spec he created to define a brand-new security category for agents that take real actions, not just generate text. We get into why the action boundary is the security boundary, why securing the model, prompt, or orchestration layer is the wrong place to enforce, and

Self-Driving Infrastructure Starts with Security: Malte Ubl, CTO of Vercel, on Vercel's New deepsec Security Harness
Malte Ubl, CTO at Vercel, joins us to discuss deepsec, Vercel's open-source AI security harness designed to scan entire codebases for vulnerabilities using coding agents like Claude and Codex. We explore why software engineering is shifting from programming models to programming agent harnesses, how deepsec scales security reviews across millions of lines of code, when AI token spend is justif

Governing AI Agents Means Governing Intent: The AWARE Framework with Sunil Agrawal, CISO of Glean
Sunil Agrawal, CISO at Glean and one of the authors of the AWARE Framework, joins us to discuss the new guide for governing generative and agentic AI he co-authored with Palo Alto Networks and Databricks. This framework gives CISOs a much needed playbook in a rapidly evolving threat landscape. Palo Alto's Unit 42 showing AI-assisted attacks can now reach data exfiltration in as little as 25 mi

A Dangerous Precedent Set? The US Government Yanks Fable
Alex Stamos, CPO of Corridor and past CISO at Facebook, and Andrew Becherer CISO at Socket, join us to discuss the open letter they and 100 others have signed in opposition to the US government taking down Fable after research from Amazon showed capabilities that gave the current administration pause.We discuss the potentially dangerous precent this sets, the state of the letter, and what to do wh

Auth Is Hard (And Agents Make It Harder) with Damian Schenkelman, Auth0
Why does every AI security incident seem to trace back to auth? We sit down with Damian Schenkelman, VP of Research and Development at Auth0 to discuss recent incidents in the news, MCP, the act claim chain, and the future of agent identity.The conversation digs into the core problem agents create: when an agent hands a task to a sub-agent, which calls an MCP server, which hits a SaaS API, who is

AAuth: Moving Beyond OAuth and the Future of Agent Auth
In this episode we sit down with Dick Hardt, the creator of OAuth, to talk about why the auth primitives we built for the web fall apart the moment agents start acting on our behalf. We dive in to why OAuth doesn't fit MCP, what breaks when an agent runs for hours and touches a dozen systems using your credentials, and his new protocol, AAuth: a way for developers to run agents without API key

Ep. 32 Hyper-personalized Software and Software Factories with Geoff Huntley @ Daytona Compute
We sit down with Geoff Huntley, creator of the Ralph Wiggum Loop and founder of LatentPatterns.com, to hear his take on where AI is pushing software next: hyper-personalized software, software factories, and eventually product factories that optimize themselves for revenue. With this level of hyper-personalization that AI now allows for Geoff says he finds himself asking vendors "are you a ut

Ep. 31 Sandboxes, the Infrastructure Underneath, and What that Means for Your Security Posture @ Daytona Compute
We sit down with top AI engineers such as Sherwood Callaway, founder of Sazabi, Anthony Shew, core maintainer of turborepo at Vercel, and Dexter Horthy, CEO of HumanLayer, to hear about how they are using sandboxes to make agents more performant. We also discuss the security differences amongst sandbox providers with Rene Brandel, founder of Casco. We discuss how sandboxes aren't created equal

Ep. 30 How Security Changes When Most Product Users are Agents (Mark Dorsi, RSAC)
Mark Dorsi, CISO at Netlify, sits down with us at RSAC to talk about the shift to everyone becoming a builder and how he's coding 6 hours a day and how products, including Netlify, must adapt to a world where most users are agents.

Ep. 29 From Point-in-Time Audits to Continuous Testing: AI’s Role in Transforming AppSec (Kyle Bhiro and Josh Kotrous, RSAC)
Kyle Bhiro and Josh Kotrous from Pensar join us at RSAC to discuss how AI is reshaping the entire AppSec industry. Kyle and Josh elaborate on how agentic code scanning and continuous testing is leading to AppSec market consolidation and new expectations around AppSec spend.We also explore the thought that point in time audits may make less sense for AI, which changes constantly. Given this, contin

Ep. 28 OpenAI Acquires Promptfoo (Ian Webster, RSAC)
Ian Webster, CEO and Co-Founder of promptfoo, joins us at RSAC to discuss OpenAI's recent acquisition of promptfoo. Ian discusses how appealing to both developers and security teams was key to promptfoo's go-market-strategy strategy.Ian's success offers a playbook for other AI security companies that may be targeting an acquisition and shares what's next for promptfoo at OpenAI.

Ep. 27 The AI-Driven Kill Chain and the Coming Bug Apocalypse (Alex Stamos, RSAC)
Alex Stamos, former CISO of Facebook and current Chief Product Officer at Corridor, explains how AI is reshaping the kill chain and enabling new capabilities for attackers worldwide.He also outlines what’s needed to defend against these emerging threats and how to prepare your organization for what’s coming.

Ep. 26 Context Graphs with Animesh Koratana, CEO of PlayerZero
Animesh is the CEO and founder of PlayerZero, a company using context graphs to build a complete picture of how your production software actually behaves.Animesh's X article on context graphs went viral getting over 2M views. Animesh explains what a context graph is, why you should build one, and how it can help you build a world model around why decisions get made.

Ep. 25 Pavan Kulkarni and Aaron Tainter, WorkOS FGA Launch
The agent identity conversation is back on the Insecure Agents podcast.Developers are starting to feel the pain of missing agent identity infrastructure as they think through problems like agent memory access and storage and goal based authorization for tools and resources unplanned for at agent inception. Listen to Pavan and Aaron explain how their recent Fine-Grained Authorization (FGA) launch c

Ep. 24 James Cowling, Co-Founder and CTO of Convex
James sits down to tell us about OpenClaw using Convex, how proper architectural building blocks sets you up for better security, and how the shift to agents writing all of software changes who platforms like Convex are building for.

Ep. 23 Cailyn Yong, Founder of Momo
You've heard of OpenClaw, but have you heard of Momo?Momo is built by Cailyn Yong and is a personal assistant agent for teams. Momo's memory actually works and makes it stand out against other agents such as OpenClaw. Hear from Cailyn on the AI security issues this type of agent faces, how she built Momo, and what it takes to be successful in this increasingly popular space.

Ep. 22 Kwindla Kramer, CEO of Daily and creator of Pipecat AI
In this episode we discuss the engineering and security challenges that separate POC agents from enterprise agents.Kwindla brings a wealth of knowledge on common hard agent engineering problems such as async, automatic, non-blocking context compaction, agent memory, and stateful long running agents.

Ep. 21 Peter Steinberger, Creator of Clawdbot
Listen in to learn how Peter created the best personal assistant agent to date and the security concerns at play. Personal assistant agents need lots of access to do meaningful work but there are tradeoffs between innovation and security.

Ep. 20 Feross Aboukhadijeh, Founder & CEO of Socket
Supply chain security for open source dependencies, how to protect yourself against attacks like Shai Hulud 2.0, and how AI agents introduce new security challenges.

Ep. 19 Ivan Burazin, Co-Founder & CEO of Daytona
Agents need purpose-built sandboxes that spin up in milliseconds to execute tasks like code analysis, web browsing, and data processing. Ivan addresses the hurdles around speed, security, and statefulness.

Ep. 18 Kikimora Morozova, AI Security Researcher, Trail of Bits
An attacker can hide prompt injections in images that only become to AI systems, enabling data exfiltration on production systems like Google Gemini CLI. Is weaponized image scaling a security vulnerability, or an architectural flaw in how AI systems process multi-modal inputs?

Ep. 17 OWASP Top 10 for Agentic Applications: Aaron Stanley, Ian Livingstone & Dex Horthy
We sat down to discuss the just released OWASP Top 10 for Agentic Applications, exploring critical threats like goal hijacking, remote code execution, and identity management while breaking down how to balance AI agent autonomy with deterministic guardrails and user trust.

Ep. 16 Peyton Casper, Identity & Trust at Browserbase
Browser agents need standardized ways to identify themselves and prove their legitimacy when accessing the web. We take a deeper look at credential management, scoped permissions models, telemetry for monitoring behavior, and implementing hard boundaries to prevent prompt injection and unauthorized actions for browser agents.
![Ep. 15 MCP Debate: Ian Livingstone, CEO of Keycard & Dex Horthy, CEO of HumanLayer [AI Engineer Code Summit 2025]](https://d3t3ozftmdmh3i.cloudfront.net/staging/podcast_uploaded_nologo/43571660/43571660-1780441239037-8c26bf9c5ecd2.jpg)
Ep. 15 MCP Debate: Ian Livingstone, CEO of Keycard & Dex Horthy, CEO of HumanLayer [AI Engineer Code Summit 2025]
The highly anticipated MCP debate. We explore critical questions around SDK replacement, marketplace curation, enterprise concerns, authentication challenges, and whether MCP represents a security nightmare or the future of agent systems.

Ep. 14 Bryan Russett & Alex Kesling, Co-Founders of Empathic
Bryan and Alex discuss how AI agent architecture directly impacts security posture. We take a look at everything from infrastructure-level guardrails rather than relying solely on tool-call layer protections to the cold start problem and defense-in-depth strategies against prompt injection.

Ep. 13 Samuel Colvin, Founder & CEO of Pydantic
Samuel Colvin founded Pydantic in 2017 and launched the company in 2023. He discusses MCP security vulnerabilities, AI agent authentication challenges, and the upcoming Pydantic AI Gateway for threat detection.

Ep. 12 Mackenzie Jackson, Developer & Security Advocate at Aikido Security
Mackenzie joins us to discuss AI in code security, smarter vulnerability prioritization, and Aikido's research into malicious packages in open source.

Ep. 11 Steve Vandenburg, AI Security Architect at Cotiviti
Steve Vandenburg, AI Security Architect at Cotiviti, discusses the evolving role of AI security in enterprise environments and how frameworks like NIST AI RMF, HITRUST, and the new SAIL framework translate from policy into real technical implementation.

Ep. 10 Dor Sarig, Co-Founder & CEO of Pillar Security
Dor Sarig has spent nearly two decades in cybersecurity, from offensive work with the Israeli government to leading product roles at Simulate and Perimeter 81. Now CEO of Pillar Security, a unified platform to secure the entire AI lifecycle and is behind the SAIL framework.

Ep. 9 Ian Livingstone, Co-Founder & CEO of Keycard
This week we're taking a deep dive on the agent identity problem. Ian Livingstone, Matt Creager and Jared Hanson founded Keycard to accelerate agent adoption without sacrificing control.

Ep. 8 John Sotiropoulos, Co-Lead of OWASP ASI and Head of AI Security at Kainos
John has written books on adversarial AI, guidelines for the UK government and laid out the globally adopted OWASP LLM Top 10. On this episode of Insecure Agents, he discuss the upcoming release of the OWASP Agentic Top 10.

Ep. 7 Kyle Ryan, Head of Artificial Intelligence at Dune Security
Dune Security simulates AI-driven social engineering attacks—like phishing, smishing, and voice cloning—to identify and train at-risk employees before real breaches occur. On this episode, Kyle Ryan discusses how generative AI is supercharging phishing tactics, how Dune adapts training to individuals’ vulnerabilities, and why both humans and AI agents must be hardened against persuasion-based atta

Ep. 6 Aengus Lynch, AI Safety Researcher
Aengus Lynch is a doing a PhD in ML, is a contractor for Anthropic, and is working on something new. Following his viral research, he joins Insecure Agents to discuss the concerning potential for AI agents to engage in blackmail and manipulation tactics against humans.

Ep 5. Harry Wetherald, CEO of Maze
After launching with $31 million in funding, Harry Wetherald, CEO of Maze, joins Insecure Agents to discuss why every security tool will be rewritten in the next 5 years.

Ep. 4 Vineeth Sai Narajala, Co-Leader of OWASP Agentic AI Top 10
Vineeth is a busy guy. He co-leads key initiatives at OWASP, including the Agent Name Service (ANS), the AI Vulnerability Scoring System (AI‑VSS) and the Agentic AI Top 10.

Ep. 3 Kerem Proulx, Co-Founder of Pensar
Kerem Proulx is Co-Founder of Pensar, the security layer for coding agents. In front of a live audience during New York Tech Week 2025, we discuss agent orchestration security concerns, identity security in a post AI agent world and AI agents becoming primary users of products.

Ep. 2 Tamir Ishay Sharbat, AI Researcher at Zenity
Tamir shares thoughts on the recent addition of AI "Darth Vader" to Fortnite, how to jailbreak voice agents, and what can go wrong when AI security falls short.

Ep. 1 Mark Dorsi, CISO of Netlify
A deep dive with Mark Dorsi, the CISO of Netlify. Live recorded during RSA Conference 2025.











