Insecure Agents is a podcast that curates the most important conversations and trends in AI security. AI engineers, CISOs, and security practitioners listen to learn how to give their agents the security they need to reach higher levels of capability and autonomy.

Allie Howe

ALLIE HOWE HOST

Allie Howe is a Member of Technical Staff at Keycard and has a background in security engineering. She is a core contributor to the OWASP Agentic Security Initiative and has spoken at AI Engineer World's Fair and AI Agent Security Summit.

𝕏 @vtahowe in /allisonhowe

Diana Kelley — CISO at Noma
#45 Jul 17

The Shared Security Model for AI Agents: Diana Kelley, CISO of Noma

We sit down with Diana Kelley, CISO at Noma, who has spent years on the front lines of enterprise security across IBM, Symantec, and Microsoft and now helps write the rulebook for the agent era. Diana makes the case that the cloud shared responsibility model does not… More on “The Shared Security Model for AI Agents: Diana Kelley, CISO of Noma”

Dick Hardt — Founder of AAuth, Creator of OAuth
#44 Jul 15

Dick Hardt, founder of AAuth, Recaps AAuth Night: Moving Beyond OAuth at AI Engineer World's Fair

We sit down with Dick Hardt, the creator of OAuth and founder of AAuth, to recap AAuth Night: Moving Beyond OAuth, our AI Engineer World's Fair side event from July 1st 2026. Dick walks us through the challenges with agent auth today, the best practices teams can lean… More on “Dick Hardt, founder of AAuth, Recaps AAuth Night: Moving Beyond OAuth at AI Engineer World's Fair”

Guy Podjarny — founder of Tessl and Snyk
#42 Jul 14

Skills Are the New Code: How We Secure the Context Our Agents Consume, with Guy Podjarny (Tessl)

We sit down with Guy Podjarny, founder of Tessl and Snyk, to make the case that skills are the new code. Guy built Snyk into the company that taught developers to secure their dependencies, and now he argues that agent skills have become a new unit of software, one… More on “Skills Are the New Code: How We Secure the Context Our Agents Consume, with Guy Podjarny (Tessl)”

Karl McGuinness — former Chief Product Architect at Okta
#41 Jun 29

The Grant Behind Enterprise Managed Auth for Claude: ID-JAG with Karl McGuinness (ex-Okta)

We sit down with Karl McGuinness, former Chief Product Architect at Okta and the author of ID-JAG, to dig into the OAuth problem that agents are about to make much worse. Karl walks us through what he calls OAuth islands, the separate OAuth stacks scattered across… More on “The Grant Behind Enterprise Managed Auth for Claude: ID-JAG with Karl McGuinness (ex-Okta)”

Derek Meegan — Software Engineer at Browserbase
#40 Jun 26

One Harness, Zero Standing Secrets: Derek Meegan (Browserbase) on Building bb

We sit down with Derek Meegan, a software engineer at Browserbase and the lead behind their internal AI agent bb, to dig into how a well-built harness, not more model autonomy, is what makes agents safe to scale. Derek explains how bb reached 100% feature-request… More on “One Harness, Zero Standing Secrets: Derek Meegan (Browserbase) on Building bb”

David Cramer — CPO and Co-Founder of Sentry
#39 Jun 24

It's the Harness, Not the Model: David Cramer, CPO of Sentry, on Agents, Expectations vs Reality

We sit down with David Cramer, CPO and co-founder of Sentry, to cut through the agent hype with a working engineer's skepticism: the model is rarely what holds agents back, the harness you build around it is. We get into the Railway incident, where a coding agent found… More on “It's the Harness, Not the Model: David Cramer, CPO of Sentry, on Agents, Expectations vs Reality”

Herman Errico — Product Manager for Technical Research at Vanta
#38 Jun 22

From Spec to Standard: How AARM Became the Conformance Bar for Agent Runtime Security, with Herman Errico (Vanta, AARM)

We sit down with Herman Errico, Product Manager for Technical Research at Vanta, to dig into AARM (Autonomous Action Runtime Management), the spec he wrote to define a new security category for agents that take real actions rather than just generate text. We get into… More on “From Spec to Standard: How AARM Became the Conformance Bar for Agent Runtime Security, with Herman Errico (Vanta, AARM)”

Malte Ubl — CTO at Vercel
#37 Jun 18

Self-Driving Infrastructure Starts with Security: Malte Ubl, CTO of Vercel, on Vercel's New deepsec Security Harness

We sit down with Malte Ubl, CTO of Vercel, to dig into deepsec, Vercel's open-source AI security harness that scans entire codebases for vulnerabilities using coding agents like Claude and Codex. We get into why software engineering is shifting from programming models… More on “Self-Driving Infrastructure Starts with Security: Malte Ubl, CTO of Vercel, on Vercel's New deepsec Security Harness”

Sunil Agrawal — CISO at Glean
#36 Jun 16

Governing AI Agents Means Governing Intent: The AWARE Framework with Sunil Agrawal, CISO of Glean

We sit down with Sunil Agrawal, CISO at Glean and co-author of the AWARE Framework, to dig into a new governance guide for generative and agentic AI built with Palo Alto Networks and Databricks. We get into AWARE's five behavioral dimensions, why governing agents means… More on “Governing AI Agents Means Governing Intent: The AWARE Framework with Sunil Agrawal, CISO of Glean”

Damian Schenkelman — VP of R&D at Auth0
#34 Jun 8

Auth Is Hard (And Agents Make It Harder) with Damian Schenkelman, Auth0

We sit down with Damian Schenkelman, VP of R&D at Auth0, to dig into why so many AI security incidents trace back to auth. We dig into recent incidents in the news, MCP, the act claim chain, and the future of agent identity. The conversation explores the core problem… More on “Auth Is Hard (And Agents Make It Harder) with Damian Schenkelman, Auth0”

Geoff Huntley — Founder of LatentPatterns.com
#32 May 7

Hyper-personalized Software and Software Factories with Geoff Huntley @ Daytona Compute

We sit down with Geoff Huntley, creator of the Ralph Wiggum Loop and founder of LatentPatterns.com, to hear his take on where AI is pushing software next: hyper-personalized software, software factories, and eventually product factories that optimize themselves for… More on “Hyper-personalized Software and Software Factories with Geoff Huntley @ Daytona Compute”

Kyle Bhiro and Josh Kotrous — Pensar
#29 Apr 2

From Point-in-Time Audits to Continuous Testing: AI’s Role in Transforming AppSec (Kyle Bhiro and Josh Kotrous, RSAC)

Kyle Bhiro and Josh Kotrous from Pensar join us at RSAC to discuss how AI is reshaping the entire AppSec industry. Kyle and Josh elaborate on how agentic code scanning and continuous testing is leading to AppSec market consolidation and new expectations around AppSec… More on “From Point-in-Time Audits to Continuous Testing: AI’s Role in Transforming AppSec (Kyle Bhiro and Josh Kotrous, RSAC)”

Alex Stamos — Chief Product Officer at Corridor
#27 Apr 1

The AI-Driven Kill Chain and the Coming Bug Apocalypse (Alex Stamos, RSAC)

Alex Stamos, former CISO of Facebook and current Chief Product Officer at Corridor, explains how AI is reshaping the kill chain and enabling new capabilities for attackers worldwide. He also outlines what’s needed to defend against these emerging threats and how to… More on “The AI-Driven Kill Chain and the Coming Bug Apocalypse (Alex Stamos, RSAC)”

Aaron Stanley — CISO of dbt Labs, Ian Livingstone, CEO of Keycard & Dex Horthy, CEO of Human Layer
#17 Dec 18

OWASP Top 10 for Agentic Applications: Aaron Stanley, Ian Livingstone & Dex Horthy

We sat down to discuss the just released OWASP Top 10 for Agentic Applications, exploring critical threats like goal hijacking, remote code execution, and identity management while breaking down how to balance AI agent autonomy with deterministic guardrails and user… More on “OWASP Top 10 for Agentic Applications: Aaron Stanley, Ian Livingstone & Dex Horthy”

Kyle Ryan — Head of Artificial Intelligence at Dune Security
#7 Jul 24

Kyle Ryan,
Head of Artificial Intelligence at Dune Security

Dune Security simulates AI-driven social engineering attacks—like phishing, smishing, and voice cloning—to identify and train at-risk employees before real breaches occur. On this episode, Kyle Ryan discusses how generative AI is supercharging phishing tactics, how… More on “Kyle Ryan, Head of Artificial Intelligence at Dune Security”