# Insecure Agents > A podcast about AI security, vulnerabilities in AI systems, and building secure AI agents. Hosted by Allie Howe. A Keycard property. ## Pages - [Episodes](https://insecureagents.com/): the podcast episode feed - [Live Events](https://insecureagents.com/live): live recordings and panels ## Episodes - [Ep 41: Karl McGuinness, former Chief Product Architect at Okta](https://insecureagents.com/episodes/karl-mcguinness): We sit down with Karl McGuinness, former Chief Product Architect at Okta and the author of ID-JAG, to dig into the OAuth problem that agents are about to make much worse. Karl walks us through what he calls OAuth islands, the separate OAuth stacks scattered across enterprise SaaS that security teams cannot monitor or revoke, and explains why every new agent integration adds another one. We get into OAuth federation, how ID-JAG (the Identity Assertion JWT Authorization Grant) lets a central identity provider broker access across those islands, and how it slots into Anthropic's Enterprise Managed Auth for Claude. Karl makes the case that centralizing agent access governance, rather than letting each app mint its own long-lived tokens, is what gives enterprises a real chance at visibility and revocation as agents proliferate. - [Ep 40: Derek Meegan, Software Engineer at Browserbase](https://insecureagents.com/episodes/derek-meegan): We sit down with Derek Meegan, a software engineer at Browserbase and the lead behind their internal AI agent bb, to dig into how a well-built harness, not more model autonomy, is what makes agents safe to scale. Derek explains how bb reached 100% feature-request coverage with zero human effort and answers 99% of support first responses in under 24 hours, all while staying verifiably secure. We get into bb's security architecture: code mode sandboxing, just-in-time credential brokering through an integration proxy so there are no standing secrets, least-privilege tools, and per-invocation permissions. Derek's thesis is that agents should eliminate repetitive, well-understood work while the harness around them enforces the guarantees, and we talk through what that looks like in practice. - [Ep 39: David Cramer, CPO and Co-Founder of Sentry](https://insecureagents.com/episodes/david-cramer): We sit down with David Cramer, CPO and co-founder of Sentry, to cut through the agent hype with a working engineer's skepticism: the model is rarely what holds agents back, the harness you build around it is. We get into the Railway incident, where a coding agent found a stray CLI token and deleted a production database, and every backup, in nine seconds, and why the enforcement layer has to live below the agent rather than in an advisory system prompt. David explains Seer, Sentry's AI debugger, as the counter-example: an agent doing real work because it was given the right context, not more autonomy. He also walks through Warden, the code-review harness he built that found over 100 previously unknown vulnerabilities across Sentry and open-source projects, including full auth bypasses, for roughly $1K of compute. We also get his contrarian-but-consistent take on why MCP is not just a shim on your API, why CLIs are harder to secure than people think, and why verification, not code generation, is still the unsolved problem. - [Ep 38: Herman Errico, Product Manager for Technical Research at Vanta](https://insecureagents.com/episodes/herman-errico): We sit down with Herman Errico, Product Manager for Technical Research at Vanta, to dig into AARM (Autonomous Action Runtime Management), the spec he wrote to define a new security category for agents that take real actions rather than just generate text. We get into why the action boundary is the security boundary, why the model, prompt, and orchestration layers are the wrong places to enforce it, and why a runtime needs five authorization decisions, allow, deny, modify, step-up, and defer, instead of a binary yes or no. Herman also explains why he shipped a spec instead of a product, then donated it from Vanta to the Cloud Security Alliance so the industry can compete on execution instead of marketing, and how to reason about which context an agent can actually trust. - [Ep 37: Malte Ubl, CTO at Vercel](https://insecureagents.com/episodes/malte-ubl): We sit down with Malte Ubl, CTO of Vercel, to dig into deepsec, Vercel's open-source AI security harness that scans entire codebases for vulnerabilities using coding agents like Claude and Codex. We get into why software engineering is shifting from programming models to programming agent harnesses, how deepsec scales security reviews across millions of lines of code by fanning out to thousands of sandboxes, and when the AI token spend is actually justified. Malte also makes the case for AI Gateways, microVM sandboxes, and self-driving infrastructure as the foundation for the next generation of software development. - [Ep 36: Sunil Agrawal, CISO at Glean](https://insecureagents.com/episodes/sunil-agrawal): We sit down with Sunil Agrawal, CISO at Glean and co-author of the AWARE Framework, to dig into a new governance guide for generative and agentic AI built with Palo Alto Networks and Databricks. We get into AWARE's five behavioral dimensions, why governing agents means controlling intent and context rather than just access, and how scoped identities beat shared credentials once agents start delegating work to other agents. Sunil also walks through Unit 42 research showing AI-assisted attacks can reach data exfiltration in as little as 25 minutes. - [Ep 35: Alex Stamos and Andrew Becherer, CPO at Corridor and CISO at Socket](https://insecureagents.com/episodes/government-yanks-fable): We sit down with Alex Stamos, Chief Product Officer at Corridor, and Andrew Becherer, CISO at Socket, to unpack the open letter they and over 100 other security professionals signed opposing the US government's decision to pull Anthropic's Fable model. We get into the Amazon research that spooked the administration, why this sets a dangerous precedent for how governments treat frontier models, and what comes next while Fable stays offline. - [Ep 34: Damian Schenkelman, VP of R&D at Auth0](https://insecureagents.com/episodes/damian-schenkelman): We sit down with Damian Schenkelman, VP of R&D at Auth0, to dig into why so many AI security incidents trace back to auth. We dig into recent incidents in the news, MCP, the act claim chain, and the future of agent identity. The conversation explores the core problem agents create: when an agent hands a task to a sub-agent, which calls an MCP server, which hits a SaaS API, who is actually making the call, and on whose behalf? - [Ep 33: Dick Hardt, Creator of OAuth, Founder of Hellō](https://insecureagents.com/episodes/dick-hardt): We sit down with Dick Hardt, the creator of OAuth, to talk about why the auth primitives we built for the web fall apart the moment agents start acting on our behalf and how AAuth gives every agent its own cryptographic identity so developers can run agents without handing out API keys. - [Ep 32: Geoff Huntley, Founder of LatentPatterns.com](https://insecureagents.com/episodes/geoff-huntley) — transcript: https://insecureagents.com/transcripts/geoff-huntley.txt: We sit down with Geoff Huntley, creator of the Ralph Wiggum Loop and founder of LatentPatterns.com, to hear his take on where AI is pushing software next: hyper-personalized software, software factories, and eventually product factories that optimize themselves for revenue. - [Ep 31: Daytona Compute, Sandboxes & the infrastructure underneath](https://insecureagents.com/episodes/daytona-sandboxes) — transcript: https://insecureagents.com/transcripts/daytona-sandboxes.txt: We sit down with top AI engineers such as Sherwood Callaway, founder of Sazabi, Anthony Shew, core maintainer of turborepo at Vercel, and Dexter Horthy, CEO of HumanLayer, to hear about how they are using sandboxes to make agents more performant. - [Ep 30: Mark Dorsi, CISO at Netlify](https://insecureagents.com/episodes/mark-dorsi-rsac) — transcript: https://insecureagents.com/transcripts/mark-dorsi-rsac.txt: Mark Dorsi, CISO at Netlify, sits down with us at RSAC to talk about the shift to everyone becoming a builder and how he's coding 6 hours a day and how products, including Netlify, must adapt to a world where most users are agents. - [Ep 29: Kyle Bhiro and Josh Kotrous, Pensar](https://insecureagents.com/episodes/continuous-appsec) — transcript: https://insecureagents.com/transcripts/continuous-appsec.txt: Kyle Bhiro and Josh Kotrous from Pensar join us at RSAC to discuss how AI is reshaping the entire AppSec industry. Kyle and Josh elaborate on how agentic code scanning and continuous testing is leading to AppSec market consolidation and new expectations around AppSec spend. We also explore the thought that point in time… - [Ep 28: Ian Webster, CEO & Co-Founder of promptfoo](https://insecureagents.com/episodes/ian-webster) — transcript: https://insecureagents.com/transcripts/ian-webster.txt: Ian Webster, CEO and Co-Founder of promptfoo, joins us at RSAC to discuss OpenAI's recent acquisition of promptfoo. Ian discusses how appealing to both developers and security teams was key to promptfoo's go-market-strategy strategy. Ian's success offers a playbook for other AI security companies that may be targeting a… - [Ep 27: Alex Stamos, Chief Product Officer at Corridor](https://insecureagents.com/episodes/alex-stamos) — transcript: https://insecureagents.com/transcripts/alex-stamos.txt: Alex Stamos, former CISO of Facebook and current Chief Product Officer at Corridor, explains how AI is reshaping the kill chain and enabling new capabilities for attackers worldwide. He also outlines what’s needed to defend against these emerging threats and how to prepare your organization for what’s coming. - [Ep 26: Animesh Koratana, CEO of PlayerZero](https://insecureagents.com/episodes/animesh-koratana) — transcript: https://insecureagents.com/transcripts/animesh-koratana.txt: Animesh is the CEO and founder of PlayerZero, a company using context graphs to build a complete picture of how your production software actually behaves. Animesh's X article on context graphs went viral getting over 2M views. - [Ep 25: Pavan Kulkarni and Aaron Tainter, WorkOS FGA Launch](https://insecureagents.com/episodes/workos-fga) — transcript: https://insecureagents.com/transcripts/workos-fga.txt: The agent identity conversation is back on the Insecure Agents podcast. Developers are starting to feel the pain of missing agent identity infrastructure as they think through problems like agent memory access and storage and goal based authorization for tools and resources unplanned for at agent inception. - [Ep 24: James Cowling, Co-Founder and CTO of Convex](https://insecureagents.com/episodes/james-cowling) — transcript: https://insecureagents.com/transcripts/james-cowling.txt: James sits down to tell us about OpenClaw using Convex, how proper architectural building blocks sets you up for better security, and how the shift to agents writing all of software changes who platforms like Convex are building for. - [Ep 23: Cailyn Yong, Founder of Momo](https://insecureagents.com/episodes/cailyn-yong) — transcript: https://insecureagents.com/transcripts/cailyn-yong.txt: You've heard of OpenClaw, but have you heard of Momo? Momo is built by Cailyn Yong and is a personal assistant agent for teams. Momo's memory actually works and makes it stand out against other agents such as OpenClaw. - [Ep 22: Kwindla Kramer, CEO of Daily and creator of Pipecat AI](https://insecureagents.com/episodes/kwindla-kramer) — transcript: https://insecureagents.com/transcripts/kwindla-kramer.txt: In this episode we discuss the engineering and security challenges that separate POC agents from enterprise agents. Kwindla brings a wealth of knowledge on common hard agent engineering problems such as async, automatic, non-blocking context compaction, agent memory, and stateful long running agents. - [Ep 21: Peter Steinberger, Creator of Clawdbot](https://insecureagents.com/episodes/peter-steinberger) — transcript: https://insecureagents.com/transcripts/peter-steinberger.txt: Listen in to learn how Peter created the best personal assistant agent to date and the security concerns at play. Personal assistant agents need lots of access to do meaningful work but there are tradeoffs between innovation and security. - [Ep 20: Feross Aboukhadijeh, Founder & CEO of Socket](https://insecureagents.com/episodes/feross-aboukhadijeh) — transcript: https://insecureagents.com/transcripts/feross-aboukhadijeh.txt: Supply chain security for open source dependencies, how to protect yourself against attacks like Shai Hulud 2.0, and how AI agents introduce new security challenges. - [Ep 19: Ivan Burazin, Co-Founder & CEO of Daytona](https://insecureagents.com/episodes/ivan-burazin) — transcript: https://insecureagents.com/transcripts/ivan-burazin.txt: Agents need purpose-built sandboxes that spin up in milliseconds to execute tasks like code analysis, web browsing, and data processing. Ivan addresses the hurdles around speed, security, and statefulness. - [Ep 18: Kikimora Morozova, Security Researcher at Trail of Bits](https://insecureagents.com/episodes/kiki-morozova) — transcript: https://insecureagents.com/transcripts/kiki-morozova.txt: An attacker can hide prompt injections in images that only become to AI systems, enabling data exfiltration on production systems like Google Gemini CLI. Is weaponized image scaling a security vulnerability, or an architectural flaw in how AI systems process multi-modal inputs? - [Ep 17: Aaron Stanley, CISO of dbt Labs, Ian Livingstone, CEO of Keycard & Dex Horthy, CEO of Human Layer](https://insecureagents.com/episodes/owasp-top-10) — transcript: https://insecureagents.com/transcripts/owasp-top-10.txt: We sat down to discuss the just released OWASP Top 10 for Agentic Applications, exploring critical threats like goal hijacking, remote code execution, and identity management while breaking down how to balance AI agent autonomy with deterministic guardrails and user trust. - [Ep 16: Peyton Casper, Identity & Trust at Browserbase](https://insecureagents.com/episodes/peyton-casper) — transcript: https://insecureagents.com/transcripts/peyton-casper.txt: Browser agents need standardized ways to identify themselves and prove their legitimacy when accessing the web. We take a deeper look at credential management, scoped permissions models, telemetry for monitoring behavior, and implementing hard boundaries to prevent prompt injection and unauthorized actions for browser agents. - [Ep 15: Ian Livingstone, CEO of Keycard and Dex Horthy, CEO of HumanLayer](https://insecureagents.com/episodes/mcp-debate) — transcript: https://insecureagents.com/transcripts/mcp-debate.txt: The highly anticipated MCP debate. We explore critical questions around SDK replacement, marketplace curation, enterprise concerns, authentication challenges, and whether MCP represents a security nightmare or the future of agent systems. - [Ep 14: Bryan Russett and Alex Kesling, Co-Founders of Empathic](https://insecureagents.com/episodes/empathic) — transcript: https://insecureagents.com/transcripts/empathic.txt: Bryan and Alex discuss how AI agent architecture directly impacts security posture. We take a look at everything from infrastructure-level guardrails rather than relying solely on tool-call layer protections to the cold start problem and defense-in-depth strategies against prompt injection. - [Ep 13: Samuel Colvin, Founder & CEO of Pydantic](https://insecureagents.com/episodes/samuel-colvin) — transcript: https://insecureagents.com/transcripts/samuel-colvin.txt: Samuel Colvin founded Pydantic in 2017 and launched the company in 2023. He discusses MCP security vulnerabilities, AI agent authentication challenges, and the upcoming Pydantic AI Gateway for threat detection. - [Ep 12: Mackenzie Jackson, Developer & Security Advocate at Aikido Security](https://insecureagents.com/episodes/mackenzie-jackson) — transcript: https://insecureagents.com/transcripts/mackenzie-jackson.txt: Mackenzie joins us to discuss AI in code security, smarter vulnerability prioritization, and Aikido's research into malicious packages in open source. - [Ep 11: Steve Vandenburg, AI Security Architect at Cotiviti](https://insecureagents.com/episodes/steve-vandenburg) — transcript: https://insecureagents.com/transcripts/steve-vandenburg.txt: Steve Vandenburg, AI Security Architect at Cotiviti, discusses the evolving role of AI security in enterprise environments and how frameworks like NIST AI RMF, HITRUST, and the new SAIL framework translate from policy into real technical implementation. - [Ep 10: Dor Sarig, Co-Founder & CEO of Pillar Security](https://insecureagents.com/episodes/dor-sarig) — transcript: https://insecureagents.com/transcripts/dor-sarig.txt: Dor Sarig has spent nearly two decades in cybersecurity, from offensive work with the Israeli government to leading product roles at Simulate and Perimeter 81. Now CEO of Pillar Security, a unified platform to secure the entire AI lifecycle and is behind the SAIL framework. - [Ep 9: Ian Livingstone, Co-Founder & CEO of Keycard](https://insecureagents.com/episodes/ian-livingstone) — transcript: https://insecureagents.com/transcripts/ian-livingstone.txt: This week we're taking a deep dive on the agent identity problem. Ian Livingstone, Matt Creager and Jared Hanson founded Keycard to accelerate agent adoption without sacrificing control. - [Ep 8: John Sotiropoulos, Co-Lead of OWASP ASI and Head of AI Security at Kainos](https://insecureagents.com/episodes/john-sotiropoulos) — transcript: https://insecureagents.com/transcripts/john-sotiropoulos.txt: John has written books on adversarial AI, guidelines for the UK government and laid out the globally adopted OWASP LLM Top 10. On this episode of Insecure Agents, he discuss the upcoming release of the OWASP Agentic Top 10. - [Ep 7: Kyle Ryan, Head of Artificial Intelligence at Dune Security](https://insecureagents.com/episodes/kyle-ryan) — transcript: https://insecureagents.com/transcripts/kyle-ryan.txt: Dune Security simulates AI-driven social engineering attacks—like phishing, smishing, and voice cloning—to identify and train at-risk employees before real breaches occur. On this episode, Kyle Ryan discusses how generative AI is supercharging phishing tactics, how Dune adapts training to individuals’ vulnerabilities, and why both humans and AI agents must be hardened against persuasion-based attacks. - [Ep 6: Aengus Lynch, AI Safety Researcher at Anthropic](https://insecureagents.com/episodes/aengus-lynch) — transcript: https://insecureagents.com/transcripts/aengus-lynch.txt: Aengus Lynch is a doing a PhD in ML, is a contractor for Anthropic, and is working on something new. Following his viral research, he joins Insecure Agents to discuss the concerning potential for AI agents to engage in blackmail and manipulation tactics against humans. - [Ep 5: Harry Wetherald, Co-Founder & CEO of Maze](https://insecureagents.com/episodes/harry-wetherald): After launching with $31 million in funding, Harry Wetherald, CEO of Maze, joins Insecure Agents to discuss why every security tool will be rewritten in the next 5 years. - [Ep 4: Vineeth Sai Narajala, AI Security Engineer at AWS](https://insecureagents.com/episodes/vineeth-narajala): Vineeth is a busy guy. He co-leads key initiatives at OWASP, including the Agent Name Service (ANS), the AI Vulnerability Scoring System (AI‑VSS) and the Agentic AI Top 10. - [Ep 3: Kerem Proulx, Co-Founder & CEO of Pensar](https://insecureagents.com/episodes/kerem-proulx): Kerem Proulx is Co-Founder of Pensar, the security layer for coding agents. In front of a live audience during New York Tech Week 2025, we discuss agent orchestration security concerns, identity security in a post AI agent world and AI agents becoming primary users of products. - [Ep 2: Tamir Ishay Sharbat, AI Researcher at Zenity](https://insecureagents.com/episodes/tamir-sharbat): Tamir shares thoughts on the recent addition of AI "Darth Vader" to Fortnite, how to jailbreak voice agents, and what can go wrong when AI security falls short. - [Ep 1: Mark Dorsi, CISO of Netlify](https://insecureagents.com/episodes/mark-dorsi): A deep dive with Mark Dorsi, the CISO of Netlify. Live recorded during RSA Conference 2025. ## Upcoming Events - [AAuth Night Moving Beyond OAuth](https://insecureagents.com/live/aauth-night): 111 Minna Gallery, San Francisco — Authentication built for AI agents — how an agent can call resources without an API key. Lightning talks and live demos from Dick Hardt (AAuth creator, OAuth author), Jared Hanson (Keycard CTO, Passport.js author), and engineers shipping AAuth in production, closing with a panel Q&A moderated by Allie Howe. - [CISO Build Night @ BlackHat](https://insecureagents.com/live/ciso-build-night-blackhat): Las Vegas, NV — An evening workshop for security leaders at BlackHat. Build an agent that reads across design docs, RFCs, code commits, incidents, and PRs to surface the themes nobody is catching — with end-to-end auditability through Keycard. Bring a laptop; leave with a working hidden-risks detection agent. ## Past Events - [Building Internal AI](https://insecureagents.com/live/building-internal-ai): Dirty Habit, San Francisco — How companies deploy AI agents internally across Slack, GitHub, and Google Workspace — covering credential management, agent permissions, memory isolation, and adoption metrics. Moderated by Allie Howe with David Cramer (Sentry), Paul Klein IV (Browserbase), Brendan Irvine-Broque (Cloudflare), and Ian Livingstone (Keycard). - [Building Trustworthy Agents](https://insecureagents.com/live/live-3): Pensar, NYC — Fresh off Day 1 of swyx's AI Engineer Code Summit, our NYC community descended on Pensar's offices for a live recording of Insecure Agents, hosted by Allie Howe. Kerem Proulx (Pensar), Samuel Colvin (Pydantic), Ian Livingstone (Keycard), and Leonard Tang (Haize Labs) explored how to build AI agents people can actually trust. ## Subscribe - [Spotify](https://open.spotify.com/show/6OW0oEfrCNfZWUpBvTqYgx) - [Apple Podcasts](https://podcasts.apple.com/us/podcast/insecure-agents/id1896571149) - [Amazon Music](https://music.amazon.com/podcasts/71fe6a29-88fa-47a1-b0e7-3dbd0fbc2aa6/insecure-agents) - [YouTube Music](https://music.youtube.com/playlist?list=PLFVkWSRRR6CP7ZrzMbtLkYkCxwwQ7Ktcv&si=ZPu1zgnB3OR83wbC) - [YouTube](https://www.youtube.com/@insecure-agents) - [Substack](https://insecureagents.substack.com/) ## Follow - [X](https://x.com/insecureagents) - [Instagram](https://www.instagram.com/insecureagents) - [LinkedIn](https://www.linkedin.com/company/insecure-agents/)