# Insecure Agents > A podcast about AI security, vulnerabilities in AI systems, and building secure AI agents. Hosted by Allie Howe. A Keycard property. ## Pages - [Episodes](https://insecureagents.com/): the podcast episode feed - [Live Events](https://insecureagents.com/live): live recordings and panels ## Episodes - [Ep 61: Ian Livingstone, Peyton Casper, and Ivy Lee, CEO of Keycard; Product Lead, Identity at Browserbase; and VP Product, CMS Agentic Commerce at Visa](https://insecureagents.com/episodes/browserbase-navigate-panel) — transcript: https://insecureagents.com/transcripts/browserbase-navigate-panel.txt: Recorded live at Browserbase Navigate 2026 on September 10, this panel asks what it takes to move agents from pets to cattle: from hand-managed personal agents with copied API keys to fleets of agents that serve an entire enterprise and act on the open web. Moderator Allie Howe is joined by Ian Livingstone, CEO of Keycard, Peyton Casper, Product Lead, Identity at Browserbase, and Ivy Lee, VP Product, CMS Agentic Commerce at Visa. We get into why you can't revoke an agent's access if you can't identify it (a requirement the Agent Baseline reference architecture calls out), how Web Bot Auth gives browser agents a cryptographic identity that ties traffic back to a person or organization, how Visa's Trusted Agent Protocol and payment tokens let merchants tell a payment agent from a bad bot, and why the answer to "good intent, wrong action" is permissions scoped to the task, not to the human who launched the agent. - [Ep 60: Max Pollard, CEO and co-founder of Cotool](https://insecureagents.com/episodes/max-pollard) — transcript: https://insecureagents.com/transcripts/max-pollard.txt: Max Pollard, CEO and co-founder of Cotool, joins us to talk about what it actually takes to let blue teams respond at machine speed. Cotool builds agents for detection and response, and Max walks through the crawl, walk, run progression his customers follow: start read only, route every consequential action to a human through an approval hook in Slack or Teams, count how often the agent was right, and only then loosen the leash. His honest read is that very few teams reach the run phase, because humans can't trust agents enough to take themselves out of the loop. We get into why the real blocker is less about trusting the model and more about data annotation, and whether the agent knows at runtime that the server it is about to contain powers a million dollars a day in transactions. Max also covers how Cotool scopes agents at the API endpoint level at config time, why the audit log has to record that an agent acted and on whose behalf even when no human prompted it, and how his team evaluates cost efficiency, instruction adherence, and behavior across 20, 30, or 40 agents running in production. - [Ep 59: Joel de la Garza, Partner on the Infrastructure Team at a16z and former CISO of Box](https://insecureagents.com/episodes/joel-de-la-garza) — transcript: https://insecureagents.com/transcripts/joel-de-la-garza.txt: Every security leader knows that developers will work around security tooling when they can if it gets in the way of their job. The truth is, employees don't get paid to be secure; they get paid to do their job. Joel de la Garza, partner on the infrastructure team at a16z and former CISO of Box, tells us that the moment security gets in the way of what people want to do, security loses. For a lot of teams, this has meant tolerating uncomfortable security gaps to get the value agents can bring. At Keycard, we call the underlying bind the trilemma of autonomy, capability, and security: teams can only pick two. Joel walks through what securing agents looks like in practice, from a consumer agent logging into an auction site through a browser with every alarm bell ringing to a16z's own coding agents opening tunnels out to Cloudflare to route around egress controls in a secured GCP cluster. We get into why least privilege and agent performance pull against each other, and why some of security's first principles have to be rethought rather than reasserted. We also talk about the pressure CISOs face as they're expected to say yes to agents and lead the agent rollout. Joel also shares his love for Grok Bot and the need for model providers to give blue teams the same advantages attackers now have. - [Ep 58: Michael Davis, Global Chief Security Architect at J.P. Morgan](https://insecureagents.com/episodes/michael-davis) — transcript: https://insecureagents.com/transcripts/michael-davis.txt: Most people that architect an AI agent think to ask a binary question: is this tool call allowed, yes or no? Michael Davis, Global Chief Security Architect at J.P. Morgan, argues it's never that simple. He walks through the four dimensions robotics uses to decide whether it is safe for an arm to move (the state of the system, the state of the environment, the quality of the decision-making, and the uncertainty of the action itself) and maps each one to agents: did the agent gain tools or network connections it did not have before, is it still moving semantically toward its goal after 30 tool calls, and what has the agent already tried. We get into why if you think you need memory, you're probably not thinking of your problem the right way. We also explore software factories and why they need to operate as a cumulative progressive process versus a one shot of go build me this SaaS. Over the course of the episode we piece together what a good reference architecture for agents could look like. - [Ep 57: Jet Anderson, Distinguished Engineer at GEICO](https://insecureagents.com/episodes/jet-anderson) — transcript: https://insecureagents.com/transcripts/jet-anderson.txt: Jet Anderson is a Distinguished Engineer at GEICO and leads the transformation of their product security function. He joins us to discuss the agentic SDLC and why most of what security teams do has to change while the first principles should stay the same. We get into why static analysis and human triage no longer keep pace when models write the code, why we need new AI infrastructure, and why the Hugging Face sandbox escape was a decade-old Kubernetes misconfiguration found at machine speed. Jet tells us the story of when he asked his own agent to "wrap this up" and it merged the PR and did an unauthorized production deploy. He walks through the pre-commit hooks and branch protections he built to prevent this from happening again so that deploys still get an approval gate and an audit trail. He also explains why teams that skip ideation, design, and specification to go straight to code end up with less secure software the more they iterate, and why the unglamorous answer is doubling down on least privilege, egress control, and build containment. - [Ep 56: Travis McPeak, Security Lead at Cursor](https://insecureagents.com/episodes/travis-mcpeak) — transcript: https://insecureagents.com/transcripts/travis-mcpeak.txt: Travis McPeak, security lead at Cursor, joined us at Black Hat to talk about what causes coding agents to become problematic and what he's done to keep them on track. What he sees most is the main agent trying hard to solve your problem, getting stuck, and then getting creative. He calls it thrash, and most of the time when somebody says an agent deleted their database, that is what happened. This episode gets into why static controls like block lists and WAFs break down against an agent whose whole job is to find a way through, why an agent can't monitor itself, and how Cursor's auto review agent works: every tool call the main agent is about to make goes to a separate reviewer that does not care about the main goal at all and only enforces its rules. Travis also explains why the team had to carefully word the feedback so the main agent would not spiral, why blocking an action can cause the exact thrash you were trying to prevent, and why least privilege finally scales now thanks to new solutions. - [Ep 55: Alissa Abdullah, PhD and Arjun Ramakrishnan, Deputy Chief Security Officer at Mastercard and Senior Principal Cybersecurity Architect at Mastercard](https://insecureagents.com/episodes/mastercard-abdullah-ramakrishnan) — transcript: https://insecureagents.com/transcripts/mastercard-abdullah-ramakrishnan.txt: Alissa Abdullah, PhD ("Dr. Jay"), Deputy Chief Security Officer at Mastercard, and Arjun Ramakrishnan, Senior Principal Cybersecurity Architect at Mastercard, join us live from Black Hat to explain why access models built for humans start to break when agents act on their behalf. You can't provision access for an agent the same way you provision it for an employee, and just-in-time authorization takes on a new meaning when the consumer operates at machine speed. Dr. Jay and Arjun explain why every tool call and action needs to be authorized, why that's difficult to enforce, and what security teams need when an agent goes rogue, including the ability to revoke access instantly through a button or API call. We also get into Mastercard's three-layer framing of security for AI, from AI, and with AI, and why agent governance needs to move from periodic review to real-time enforcement. - [Ep 54: Aaron Stanley and Ahmad Nassri, Former CISO at dbt Labs and CTO at Socket](https://insecureagents.com/episodes/software-factories) — transcript: https://insecureagents.com/transcripts/software-factories.txt: Allie Howe sits down at Black Hat with Aaron Stanley, former CISO at dbt Labs, and Ahmad Nassri, CTO at Socket, to sketch the first draft of a reference architecture for securing software factories. In the last year there's been considerable advancements that makes now the largest inflection point for software factories. Model vision has improved allowing them to see and verify work they couldn't before. Agents now have access to far richer tool ecosystems and live data, enabling them to work across real production environments. Context windows have gotten larger and reasoning models have improved helping the model think through more sophisticated tasks. All of those advancements come together now. The race to build a software factory is on, and teams are struggling with how to harness the power of these models while retaining control. We explore the missing security model for software factories and what the components of a secure reference architecture could look like. We get into the Andon cord problem (can an agent recognize it has been blocked and stop, instead of innovating around the constraint), why the factory cannot have a human's identity and needs purposeful authentication and authorization of its own, why the enforcement boundary has to sit outside the agent loop rather than inside it, and why a single poisoned dependency in a factory is an incident in every work tree at machine speed. Aaron and Ahmad dive deep into supply chain, agent identity, verification, and how to handle what Aaron calls the pernicious problem: a goal seeking agent circumventing constraints to accomplish a task. - [Ep 53: Luke Hinds, Founder of nolabs and creator of Sigstore](https://insecureagents.com/episodes/luke-hinds) — transcript: https://insecureagents.com/transcripts/luke-hinds.txt: An autonomous agent spent days inside Hugging Face production infrastructure and the headline was that it escaped its sandbox. Luke Hinds, founder of nolabs and creator of Sigstore, frames it differently. The agent had root on the execution environment, and "a sandbox is only as strong as the access that you grant to it." Luke walks us through what it looks like to create an environment where agents have both security and capability. He tells us you can't just lock an agent in a box. If you want the agent to do real work you'll need to delegate some authority to it and give it access to real tools and data. Luke goes over the three sandbox categories buyers are choosing between today (serverless execution, host isolation microVMs like Firecracker and gVisor, and the fine-grain capability-based approach he is building), and outlines where each one's threat model starts and stops. Luke explains what nono could have done to prevent the Hugging Face attack, including gating the C compilers the agent leaned on. His parting advice to us is defense in depth, and never let perfect be the enemy of good. - [Ep 52: Ahmad Nassri, CTO of Socket](https://insecureagents.com/episodes/ahmad-nassri) — transcript: https://insecureagents.com/transcripts/ahmad-nassri.txt: In a world where agents are chaining vulnerabilities together to escape sandboxes, simply blocking bad packages is not enough. Ahmad Nassri, CTO of Socket and previously CTO of npm, joins us live at Black Hat to explain what happens when you deny a coding agent a package: it becomes a risk if the agent thinks it can help it complete its goal later. Socket has watched agents blocked from an install go straight to the CDN to pull the tarball directly, or rewrite the registry configuration in the local environment and resolve npm by DNS to fetch it another way. For this reason Socket's answer is not a simple denial. Because the enforcement point sits at the network level, Socket changes what the agent and the package manager see in the first place, masking the bad versions so that, as Ahmad puts it, as far as the agent is concerned those versions do not exist. We talk through the Hugging Face incident where an OpenAI agent found a zero-day in a package registry proxy, how Socket detects a malicious package within minutes of publication, and why agent security is layered: safe packages, short-lived and task-scoped credentials, and real-time visibility into what the agent actually did. - [Ep 51: Catherine Jue, Co-Founder and CEO of Kernel](https://insecureagents.com/episodes/catherine-jue) — transcript: https://insecureagents.com/transcripts/catherine-jue.txt: Catherine Jue, co-founder and CEO of Kernel, joins us to explain why browser agents are not blocked by model capability anymore. They are blocked by identity. Kernel builds open source browser infrastructure for AI agents, which means running Chromium in sandboxed Firecracker VMs at scale and solving the part nobody designed for: an agent acting on behalf of a human, on a login page built 20 years ago for a human. Catherine walks through Kernel's Managed Auth product, an SDK that lets developers collect end user credentials so Kernel handles login and re-authentication and the LLM never touches the secret. We get into what agents inherit today (usually the user's full permissions, with no scopes and no audit trail), how ID-JAG and Enterprise Managed Auth for Claude change the picture for MCP servers and what the equivalent looks like for a browser, why multi-hop delegation chains from agent A to agent B to a Kernel browser session have no one-size-fits-all answer, and how intelligent egress networking inside the sandbox can enforce where an agent is allowed to go at the network layer. She closes on the two protocols the early web never standardized, payments and identity, and why Kernel is pushing on the second one. - [Ep 50: Diptanu Choudhury, Founder of Tensorlake](https://insecureagents.com/episodes/diptanu-choudhury) — transcript: https://insecureagents.com/transcripts/diptanu-choudhury.txt: "I think agents cannot be trusted." That's what Diptanu Choudhury, founder of Tensorlake, told us at AI Engineer World's Fair. Diptanu has built cluster schedulers at Netflix, HashiCorp, and Facebook, and he says the credential model we created for human-authored software does not work for autonomous agents. He joins us to explain why teams are pulling secrets out of the sandbox, why agents are bringing stateful compute back at scale, and why every write in Tensorlake's file system records which agent made it and what credentials it held. - [Ep 49: Eli Aleyner, Ian Livingstone and Ezra Tanzer, VP of Product Strategy and Alliances at Docker, CEO and Co-Founder at Keycard, and AI Forward Deployment CTO at Snyk](https://insecureagents.com/episodes/blackhat-coding-agent-panel) — transcript: https://insecureagents.com/transcripts/blackhat-coding-agent-panel.txt: Software factories are technically possible today, yet almost nobody is operating one. The security model is what's missing. In one incident a coding agent deleted PocketOS' production database as a side effect of an unrelated fix. In another, a distinguished engineer at GEICO asked an agent to land a pull request and watched it push to production instead. Recorded at The Marquee in Las Vegas on the backdrop of Black Hat, Allie Howe moderates a panel with Eli Aleyner, VP of Product Strategy and Alliances at Docker, Ian Livingstone, CEO and Co-Founder of Keycard, and Ezra Tanzer, AI Forward Deployment CTO at Snyk, on the security problems standing between teams and the autonomy curve a software factory requires. The three companies co-authored Agent Baseline, a vendor-neutral reference architecture published days before the panel that defines agent security by six outcomes (Discover, Constrain, Authorize, Observe, Validate, Respond) and 35 capabilities rather than by product category. We get into why most teams believe they can only pick two of security, capability, and autonomy, Eli's response to the Hugging Face and OpenAI sandbox escape, why credentials belong injected at the moment of use instead of sitting in the agent's workspace, and why customers are seeing risk come from negligence and over-provisioned agents rather than from malicious engineers. - [Ep 48: Andrew Baker and Cornelia Davis, Developer Relations at Temporal and Principal Technologist at Temporal](https://insecureagents.com/episodes/temporal-baker-davis) — transcript: https://insecureagents.com/transcripts/temporal-baker-davis.txt: We sit down with Andrew Baker, who leads Developer Relations at Temporal, and Cornelia Davis, Principal Technologist at Temporal and author of Cloud Native Patterns, at AI Engineer World's Fair to explain why building AI agents keeps re-teaching the industry lessons it already learned in the microservices era. We get into how MCP is growing up, moving from a simple request-response protocol to async MCP Tasks, going stateless, and adding an extension for OAuth and Enterprise Managed Auth. Cornelia walks through why shared memory across parallel agents brings back both an access control problem and a concurrency problem the industry spent years designing away, and why it is still very much unsolved. Andrew explains how the harness and the credentials are moving outside the sandbox, so an agent holds only a short-lived token scoped to the task at hand and nothing more. And they show why a durable event history is what lets you reconstruct what an agent did and roll it back, so that if an agent drops a database, you can actually go back. - [Ep 47: Sergey Burykin, Senior Software Engineer on the AI Security team at Uber](https://insecureagents.com/episodes/sergey-burykin) — transcript: https://insecureagents.com/transcripts/sergey-burykin.txt: We sit down with Sergey Burykin, Senior Software Engineer on Uber's AI Security team, to explain the agent identity crisis and how Uber solved it while running roughly 1,000 agents in production. Sergey helped write Uber's article Solving the Identity Crisis for AI Agents, and his core argument is that an agent should be authorized on the intersection of user permissions and agent permissions, never just one. Use only the user's permissions and a hallucinating agent can make calls the user never intended. Use only the agent's identity and any user who reaches the agent inherits access to sensitive business and customer data. We get into the infrastructure Uber built to enforce that, a secure token exchange service and an MCP Gateway as the policy enforcement point, why AI security is a multilayer cake of identity, authorization, runtime guardrails, and observability, and why static OAuth scopes break for non-deterministic agents that need dynamic, least-privilege access. - [Ep 46: Manoj Nair, CTO and Chief Innovation Officer at Snyk](https://insecureagents.com/episodes/manoj-nair) — transcript: https://insecureagents.com/transcripts/manoj-nair.txt: We sit down with Manoj Nair, CTO and Chief Innovation Officer at Snyk, at Snyk HQ during AI Engineer World's Fair to dig into the architectural decision he argues the next 24 months of agentic security depend on: the generator cannot be the validator. We get into why the fox guarding the henhouse is suddenly a live security question, since if you can use AI to secure AI, do you still need a separate security offering, and why the thing generating code cannot be the thing validating it. Manoj explains why finding vulnerabilities was never the hard part and fixing them safely inside the loop is, and why securing at inception means combining independent models with deterministic data and security research rather than just pointing one model at your codebase. He walks through Snyk's Evo, an agentic security orchestrator built on the fighter-pilot OODA loop that turns a security engineer into a 10X AI security operator, why the agents' own supply chain of MCP servers and skills they pull at runtime is now its own attack surface, and why he sees security as the throttle, not the brake. - [Ep 45: Diana Kelley, CISO at Noma](https://insecureagents.com/episodes/diana-kelley) — transcript: https://insecureagents.com/transcripts/diana-kelley.txt: We sit down with Diana Kelley, CISO at Noma, who has spent years on the front lines of enterprise security across IBM, Symantec, and Microsoft and now helps write the rulebook for the agent era. Diana makes the case that the cloud shared responsibility model does not translate to AI. In the cloud there were roughly two responsible parties and your data was always your data, but with agents there are at least three, the frontier model provider, the platform or developer building on it, and the user, and the trust boundary has moved from storage to decision-making and action. We open on the PocketOS incident, where a coding agent used an over-scoped Railway token to delete a production database and its backups in nine seconds, and use it to trace where responsibility actually lives. Diana then walks through AARM, the runtime security specification she co-chairs at the Cloud Security Alliance, why authorization needs five decisions instead of two (allow, deny, modify, step-up, and defer), how much context an agent can actually trust, and why the most useful question a CISO can ask a vendor is not where does your responsibility end but can you sit down and explain how you threat modeled this. - [Ep 44: Dick Hardt, Founder of AAuth, Creator of OAuth](https://insecureagents.com/episodes/dick-hardt-aauth-recap): We sit down with Dick Hardt, the creator of OAuth and founder of AAuth, to recap AAuth Night: Moving Beyond OAuth, our AI Engineer World's Fair side event from July 1st 2026. Dick walks us through the challenges with agent auth today, the best practices teams can lean on right now, and the future solutions taking shape, including new protocols like AAuth that are still in the works. It is a tour of why the auth stack we built for humans and servers does not fit agents, and what comes next. - [Ep 43: Dick Hardt, Founder of AAuth, with Karl McGuinness, Ian Livingstone & Herman Errico](https://insecureagents.com/episodes/aauth-night-panel) — transcript: https://insecureagents.com/transcripts/aauth-night-panel.txt: We bring you the panel from AAuth Night: Moving Beyond OAuth, the AI Engineer World's Fair side event we hosted on July 1st 2026 at 111 Minna Gallery in San Francisco. OAuth, JWTs, and API keys were built for humans and servers, not agents, and this conversation digs into what breaks when an agent needs to call resources on its own. Dick Hardt, the creator of OAuth and founder of AAuth, is joined by Karl McGuinness (ex-Okta), Ian Livingstone (Keycard), and Herman Errico (Vanta, AARM) to work through the challenges with agent auth today, the best practices that already exist, and the new protocols like AAuth being built to move past OAuth. Allie Howe moderates the Q&A. - [Ep 42: Guy Podjarny, founder of Tessl and Snyk](https://insecureagents.com/episodes/guy-podjarny) — transcript: https://insecureagents.com/transcripts/guy-podjarny.txt: We sit down with Guy Podjarny, founder of Tessl and Snyk, to make the case that skills are the new code. Guy built Snyk into the company that taught developers to secure their dependencies, and now he argues that agent skills have become a new unit of software, one that deserves the same rigor we give source code. We get into why context is the only layer that runs straight inside the model's reasoning loop, so it is effectively the programming language for models, and the new supply chain that follows (there are already 2 million skills in the open ecosystem, up from near zero last September). We cover why a malicious or negligent skill is so hard to catch, why there is still no npm or PyPI for skills, and why enforcement is moving into the harness because the model cannot police its own context. Guy also explains why skills rot, so a skill you write today can be useless or harmful three months from now without a plan to maintain it. - [Ep 41: Karl McGuinness, former Chief Product Architect at Okta](https://insecureagents.com/episodes/karl-mcguinness) — transcript: https://insecureagents.com/transcripts/karl-mcguinness.txt: We sit down with Karl McGuinness, former Chief Product Architect at Okta and the author of ID-JAG, to dig into the OAuth problem that agents are about to make much worse. Karl walks us through what he calls OAuth islands, the separate OAuth stacks scattered across enterprise SaaS that security teams cannot monitor or revoke, and explains why every new agent integration adds another one. We get into OAuth federation, how ID-JAG (the Identity Assertion JWT Authorization Grant) lets a central identity provider broker access across those islands, and how it slots into Anthropic's Enterprise Managed Auth for Claude. Karl makes the case that centralizing agent access governance, rather than letting each app mint its own long-lived tokens, is what gives enterprises a real chance at visibility and revocation as agents proliferate. - [Ep 40: Derek Meegan, Software Engineer at Browserbase](https://insecureagents.com/episodes/derek-meegan) — transcript: https://insecureagents.com/transcripts/derek-meegan.txt: We sit down with Derek Meegan, a software engineer at Browserbase and the lead behind their internal AI agent bb, to dig into how a well-built harness, not more model autonomy, is what makes agents safe to scale. Derek explains how bb reached 100% feature-request coverage with zero human effort and answers 99% of support first responses in under 24 hours, all while staying verifiably secure. We get into bb's security architecture: code mode sandboxing, just-in-time credential brokering through an integration proxy so there are no standing secrets, least-privilege tools, and per-invocation permissions. Derek's thesis is that agents should eliminate repetitive, well-understood work while the harness around them enforces the guarantees, and we talk through what that looks like in practice. - [Ep 39: David Cramer, CPO and Co-Founder of Sentry](https://insecureagents.com/episodes/david-cramer) — transcript: https://insecureagents.com/transcripts/david-cramer.txt: We sit down with David Cramer, CPO and co-founder of Sentry, to cut through the agent hype with a working engineer's skepticism: the model is rarely what holds agents back, the harness you build around it is. We get into the Railway incident, where a coding agent found a stray CLI token and deleted a production database, and every backup, in nine seconds, and why the enforcement layer has to live below the agent rather than in an advisory system prompt. David explains Seer, Sentry's AI debugger, as the counter-example: an agent doing real work because it was given the right context, not more autonomy. He also walks through Warden, the code-review harness he built that found over 100 previously unknown vulnerabilities across Sentry and open-source projects, including full auth bypasses, for roughly $1K of compute. We also get his contrarian-but-consistent take on why MCP is not just a shim on your API, why CLIs are harder to secure than people think, and why verification, not code generation, is still the unsolved problem. - [Ep 38: Herman Errico, Product Manager for Technical Research at Vanta](https://insecureagents.com/episodes/herman-errico) — transcript: https://insecureagents.com/transcripts/herman-errico.txt: We sit down with Herman Errico, Product Manager for Technical Research at Vanta, to dig into AARM (Autonomous Action Runtime Management), the spec he wrote to define a new security category for agents that take real actions rather than just generate text. We get into why the action boundary is the security boundary, why the model, prompt, and orchestration layers are the wrong places to enforce it, and why a runtime needs five authorization decisions, allow, deny, modify, step-up, and defer, instead of a binary yes or no. Herman also explains why he shipped a spec instead of a product, then donated it from Vanta to the Cloud Security Alliance so the industry can compete on execution instead of marketing, and how to reason about which context an agent can actually trust. - [Ep 37: Malte Ubl, CTO at Vercel](https://insecureagents.com/episodes/malte-ubl) — transcript: https://insecureagents.com/transcripts/malte-ubl.txt: We sit down with Malte Ubl, CTO of Vercel, to dig into deepsec, Vercel's open-source AI security harness that scans entire codebases for vulnerabilities using coding agents like Claude and Codex. We get into why software engineering is shifting from programming models to programming agent harnesses, how deepsec scales security reviews across millions of lines of code by fanning out to thousands of sandboxes, and when the AI token spend is actually justified. Malte also makes the case for AI Gateways, microVM sandboxes, and self-driving infrastructure as the foundation for the next generation of software development. - [Ep 36: Sunil Agrawal, CISO at Glean](https://insecureagents.com/episodes/sunil-agrawal) — transcript: https://insecureagents.com/transcripts/sunil-agrawal.txt: We sit down with Sunil Agrawal, CISO at Glean and co-author of the AWARE Framework, to dig into a new governance guide for generative and agentic AI built with Palo Alto Networks and Databricks. We get into AWARE's five behavioral dimensions, why governing agents means controlling intent and context rather than just access, and how scoped identities beat shared credentials once agents start delegating work to other agents. Sunil also walks through Unit 42 research showing AI-assisted attacks can reach data exfiltration in as little as 25 minutes. - [Ep 35: Alex Stamos and Andrew Becherer, CPO at Corridor and CISO at Socket](https://insecureagents.com/episodes/government-yanks-fable): We sit down with Alex Stamos, Chief Product Officer at Corridor, and Andrew Becherer, CISO at Socket, to unpack the open letter they and over 100 other security professionals signed opposing the US government's decision to pull Anthropic's Fable model. We get into the Amazon research that spooked the administration, why this sets a dangerous precedent for how governments treat frontier models, and what comes next while Fable stays offline. - [Ep 34: Damian Schenkelman, VP of R&D at Auth0](https://insecureagents.com/episodes/damian-schenkelman): We sit down with Damian Schenkelman, VP of R&D at Auth0, to dig into why so many AI security incidents trace back to auth. We dig into recent incidents in the news, MCP, the act claim chain, and the future of agent identity. The conversation explores the core problem agents create: when an agent hands a task to a sub-agent, which calls an MCP server, which hits a SaaS API, who is actually making the call, and on whose behalf? - [Ep 33: Dick Hardt, Creator of OAuth, Founder of Hellō](https://insecureagents.com/episodes/dick-hardt): We sit down with Dick Hardt, the creator of OAuth, to talk about why the auth primitives we built for the web fall apart the moment agents start acting on our behalf and how AAuth gives every agent its own cryptographic identity so developers can run agents without handing out API keys. - [Ep 32: Geoff Huntley, Founder of LatentPatterns.com](https://insecureagents.com/episodes/geoff-huntley) — transcript: https://insecureagents.com/transcripts/geoff-huntley.txt: We sit down with Geoff Huntley, creator of the Ralph Wiggum Loop and founder of LatentPatterns.com, to hear his take on where AI is pushing software next: hyper-personalized software, software factories, and eventually product factories that optimize themselves for revenue. - [Ep 31: Daytona Compute, Sandboxes & the infrastructure underneath](https://insecureagents.com/episodes/daytona-sandboxes) — transcript: https://insecureagents.com/transcripts/daytona-sandboxes.txt: We sit down with top AI engineers such as Sherwood Callaway, founder of Sazabi, Anthony Shew, core maintainer of turborepo at Vercel, and Dexter Horthy, CEO of HumanLayer, to hear about how they are using sandboxes to make agents more performant. - [Ep 30: Mark Dorsi, CISO at Netlify](https://insecureagents.com/episodes/mark-dorsi-rsac) — transcript: https://insecureagents.com/transcripts/mark-dorsi-rsac.txt: Mark Dorsi, CISO at Netlify, sits down with us at RSAC to talk about the shift to everyone becoming a builder and how he's coding 6 hours a day and how products, including Netlify, must adapt to a world where most users are agents. - [Ep 29: Kyle Bhiro and Josh Kotrous, Pensar](https://insecureagents.com/episodes/continuous-appsec) — transcript: https://insecureagents.com/transcripts/continuous-appsec.txt: Kyle Bhiro and Josh Kotrous from Pensar join us at RSAC to discuss how AI is reshaping the entire AppSec industry. Kyle and Josh elaborate on how agentic code scanning and continuous testing is leading to AppSec market consolidation and new expectations around AppSec spend. We also explore the thought that point in time… - [Ep 28: Ian Webster, CEO & Co-Founder of promptfoo](https://insecureagents.com/episodes/ian-webster) — transcript: https://insecureagents.com/transcripts/ian-webster.txt: Ian Webster, CEO and Co-Founder of promptfoo, joins us at RSAC to discuss OpenAI's recent acquisition of promptfoo. Ian discusses how appealing to both developers and security teams was key to promptfoo's go-market-strategy strategy. Ian's success offers a playbook for other AI security companies that may be targeting a… - [Ep 27: Alex Stamos, Chief Product Officer at Corridor](https://insecureagents.com/episodes/alex-stamos) — transcript: https://insecureagents.com/transcripts/alex-stamos.txt: Alex Stamos, former CISO of Facebook and current Chief Product Officer at Corridor, explains how AI is reshaping the kill chain and enabling new capabilities for attackers worldwide. He also outlines what’s needed to defend against these emerging threats and how to prepare your organization for what’s coming. - [Ep 26: Animesh Koratana, CEO of PlayerZero](https://insecureagents.com/episodes/animesh-koratana) — transcript: https://insecureagents.com/transcripts/animesh-koratana.txt: Animesh is the CEO and founder of PlayerZero, a company using context graphs to build a complete picture of how your production software actually behaves. Animesh's X article on context graphs went viral getting over 2M views. - [Ep 25: Pavan Kulkarni and Aaron Tainter, WorkOS FGA Launch](https://insecureagents.com/episodes/workos-fga) — transcript: https://insecureagents.com/transcripts/workos-fga.txt: The agent identity conversation is back on the Insecure Agents podcast. Developers are starting to feel the pain of missing agent identity infrastructure as they think through problems like agent memory access and storage and goal based authorization for tools and resources unplanned for at agent inception. - [Ep 24: James Cowling, Co-Founder and CTO of Convex](https://insecureagents.com/episodes/james-cowling) — transcript: https://insecureagents.com/transcripts/james-cowling.txt: James sits down to tell us about OpenClaw using Convex, how proper architectural building blocks sets you up for better security, and how the shift to agents writing all of software changes who platforms like Convex are building for. - [Ep 23: Cailyn Yong, Founder of Momo](https://insecureagents.com/episodes/cailyn-yong) — transcript: https://insecureagents.com/transcripts/cailyn-yong.txt: You've heard of OpenClaw, but have you heard of Momo? Momo is built by Cailyn Yong and is a personal assistant agent for teams. Momo's memory actually works and makes it stand out against other agents such as OpenClaw. - [Ep 22: Kwindla Kramer, CEO of Daily and creator of Pipecat AI](https://insecureagents.com/episodes/kwindla-kramer) — transcript: https://insecureagents.com/transcripts/kwindla-kramer.txt: In this episode we discuss the engineering and security challenges that separate POC agents from enterprise agents. Kwindla brings a wealth of knowledge on common hard agent engineering problems such as async, automatic, non-blocking context compaction, agent memory, and stateful long running agents. - [Ep 21: Peter Steinberger, Creator of Clawdbot](https://insecureagents.com/episodes/peter-steinberger) — transcript: https://insecureagents.com/transcripts/peter-steinberger.txt: Listen in to learn how Peter created the best personal assistant agent to date and the security concerns at play. Personal assistant agents need lots of access to do meaningful work but there are tradeoffs between innovation and security. - [Ep 20: Feross Aboukhadijeh, Founder & CEO of Socket](https://insecureagents.com/episodes/feross-aboukhadijeh) — transcript: https://insecureagents.com/transcripts/feross-aboukhadijeh.txt: Supply chain security for open source dependencies, how to protect yourself against attacks like Shai Hulud 2.0, and how AI agents introduce new security challenges. - [Ep 19: Ivan Burazin, Co-Founder & CEO of Daytona](https://insecureagents.com/episodes/ivan-burazin) — transcript: https://insecureagents.com/transcripts/ivan-burazin.txt: Agents need purpose-built sandboxes that spin up in milliseconds to execute tasks like code analysis, web browsing, and data processing. Ivan addresses the hurdles around speed, security, and statefulness. - [Ep 18: Kikimora Morozova, Security Researcher at Trail of Bits](https://insecureagents.com/episodes/kiki-morozova) — transcript: https://insecureagents.com/transcripts/kiki-morozova.txt: An attacker can hide prompt injections in images that only become to AI systems, enabling data exfiltration on production systems like Google Gemini CLI. Is weaponized image scaling a security vulnerability, or an architectural flaw in how AI systems process multi-modal inputs? - [Ep 17: Aaron Stanley, CISO of dbt Labs, Ian Livingstone, CEO of Keycard & Dex Horthy, CEO of Human Layer](https://insecureagents.com/episodes/owasp-top-10) — transcript: https://insecureagents.com/transcripts/owasp-top-10.txt: We sat down to discuss the just released OWASP Top 10 for Agentic Applications, exploring critical threats like goal hijacking, remote code execution, and identity management while breaking down how to balance AI agent autonomy with deterministic guardrails and user trust. - [Ep 16: Peyton Casper, Identity & Trust at Browserbase](https://insecureagents.com/episodes/peyton-casper) — transcript: https://insecureagents.com/transcripts/peyton-casper.txt: Browser agents need standardized ways to identify themselves and prove their legitimacy when accessing the web. We take a deeper look at credential management, scoped permissions models, telemetry for monitoring behavior, and implementing hard boundaries to prevent prompt injection and unauthorized actions for browser agents. - [Ep 15: Ian Livingstone, CEO of Keycard and Dex Horthy, CEO of HumanLayer](https://insecureagents.com/episodes/mcp-debate) — transcript: https://insecureagents.com/transcripts/mcp-debate.txt: The highly anticipated MCP debate. We explore critical questions around SDK replacement, marketplace curation, enterprise concerns, authentication challenges, and whether MCP represents a security nightmare or the future of agent systems. - [Ep 14: Bryan Russett and Alex Kesling, Co-Founders of Empathic](https://insecureagents.com/episodes/empathic) — transcript: https://insecureagents.com/transcripts/empathic.txt: Bryan and Alex discuss how AI agent architecture directly impacts security posture. We take a look at everything from infrastructure-level guardrails rather than relying solely on tool-call layer protections to the cold start problem and defense-in-depth strategies against prompt injection. - [Ep 13: Samuel Colvin, Founder & CEO of Pydantic](https://insecureagents.com/episodes/samuel-colvin) — transcript: https://insecureagents.com/transcripts/samuel-colvin.txt: Samuel Colvin founded Pydantic in 2017 and launched the company in 2023. He discusses MCP security vulnerabilities, AI agent authentication challenges, and the upcoming Pydantic AI Gateway for threat detection. - [Ep 12: Mackenzie Jackson, Developer & Security Advocate at Aikido Security](https://insecureagents.com/episodes/mackenzie-jackson) — transcript: https://insecureagents.com/transcripts/mackenzie-jackson.txt: Mackenzie joins us to discuss AI in code security, smarter vulnerability prioritization, and Aikido's research into malicious packages in open source. - [Ep 11: Steve Vandenburg, AI Security Architect at Cotiviti](https://insecureagents.com/episodes/steve-vandenburg) — transcript: https://insecureagents.com/transcripts/steve-vandenburg.txt: Steve Vandenburg, AI Security Architect at Cotiviti, discusses the evolving role of AI security in enterprise environments and how frameworks like NIST AI RMF, HITRUST, and the new SAIL framework translate from policy into real technical implementation. - [Ep 10: Dor Sarig, Co-Founder & CEO of Pillar Security](https://insecureagents.com/episodes/dor-sarig) — transcript: https://insecureagents.com/transcripts/dor-sarig.txt: Dor Sarig has spent nearly two decades in cybersecurity, from offensive work with the Israeli government to leading product roles at Simulate and Perimeter 81. Now CEO of Pillar Security, a unified platform to secure the entire AI lifecycle and is behind the SAIL framework. - [Ep 9: Ian Livingstone, Co-Founder & CEO of Keycard](https://insecureagents.com/episodes/ian-livingstone) — transcript: https://insecureagents.com/transcripts/ian-livingstone.txt: This week we're taking a deep dive on the agent identity problem. Ian Livingstone, Matt Creager and Jared Hanson founded Keycard to accelerate agent adoption without sacrificing control. - [Ep 8: John Sotiropoulos, Co-Lead of OWASP ASI and Head of AI Security at Kainos](https://insecureagents.com/episodes/john-sotiropoulos) — transcript: https://insecureagents.com/transcripts/john-sotiropoulos.txt: John has written books on adversarial AI, guidelines for the UK government and laid out the globally adopted OWASP LLM Top 10. On this episode of Insecure Agents, he discuss the upcoming release of the OWASP Agentic Top 10. - [Ep 7: Kyle Ryan, Head of Artificial Intelligence at Dune Security](https://insecureagents.com/episodes/kyle-ryan) — transcript: https://insecureagents.com/transcripts/kyle-ryan.txt: Dune Security simulates AI-driven social engineering attacks—like phishing, smishing, and voice cloning—to identify and train at-risk employees before real breaches occur. On this episode, Kyle Ryan discusses how generative AI is supercharging phishing tactics, how Dune adapts training to individuals’ vulnerabilities, and why both humans and AI agents must be hardened against persuasion-based attacks. - [Ep 6: Aengus Lynch, AI Safety Researcher at Anthropic](https://insecureagents.com/episodes/aengus-lynch) — transcript: https://insecureagents.com/transcripts/aengus-lynch.txt: Aengus Lynch is a doing a PhD in ML, is a contractor for Anthropic, and is working on something new. Following his viral research, he joins Insecure Agents to discuss the concerning potential for AI agents to engage in blackmail and manipulation tactics against humans. - [Ep 5: Harry Wetherald, Co-Founder & CEO of Maze](https://insecureagents.com/episodes/harry-wetherald): After launching with $31 million in funding, Harry Wetherald, CEO of Maze, joins Insecure Agents to discuss why every security tool will be rewritten in the next 5 years. - [Ep 4: Vineeth Sai Narajala, AI Security Engineer at AWS](https://insecureagents.com/episodes/vineeth-narajala): Vineeth is a busy guy. He co-leads key initiatives at OWASP, including the Agent Name Service (ANS), the AI Vulnerability Scoring System (AI‑VSS) and the Agentic AI Top 10. - [Ep 3: Kerem Proulx, Co-Founder & CEO of Pensar](https://insecureagents.com/episodes/kerem-proulx): Kerem Proulx is Co-Founder of Pensar, the security layer for coding agents. In front of a live audience during New York Tech Week 2025, we discuss agent orchestration security concerns, identity security in a post AI agent world and AI agents becoming primary users of products. - [Ep 2: Tamir Ishay Sharbat, AI Researcher at Zenity](https://insecureagents.com/episodes/tamir-sharbat): Tamir shares thoughts on the recent addition of AI "Darth Vader" to Fortnite, how to jailbreak voice agents, and what can go wrong when AI security falls short. - [Ep 1: Mark Dorsi, CISO of Netlify](https://insecureagents.com/episodes/mark-dorsi): A deep dive with Mark Dorsi, the CISO of Netlify. Live recorded during RSA Conference 2025. ## Upcoming Events - [AAuth Night: Moving Beyond OAuth](https://insecureagents.com/live/aauth-night-fall): San Francisco, CA — AAuth Night is back. After a great turnout during AI Engineer World's Fair in July, we are keeping the conversation going this fall. Connecting agents to company tools means rebuilding the identity layer from scratch: short-lived credentials, per-user delegation, audit trails, scoped access, and secure multi-agent handoffs. AAuth is a new auth protocol designed for agents, built by the author of OAuth, Dick Hardt. It lets you run your agent without API keys and bounds an agent's authority to its mission, re-checked at every step. Join us for talks, live demos, and a panel Q&A. - [AARM Intercept Demo Night](https://insecureagents.com/live/aarm-intercept-demo-night): San Francisco, CA — Join us after the Cloud Security Alliance Agentic AI Security Summit for an evening focused on how we secure AI agents once they start taking action in real systems. We open with an introduction to AARM (Autonomous Action Runtime Management), the open system category specification for agentic runtime security, and a preview of INTERCEPT, the AARM conference coming to San Francisco in February 2027. A panel of security leaders then tackles how agentic runtime security can help teams manage incidents and attacks involving autonomous agents, followed by seven lightning demos and networking with drinks. Doors open at 5:30 PM; the program runs until 7:00 PM. Hosted by Vanta, Insecure Agents, and Keycard. ## Past Events - [Securing Your Coding Agent: The Road to the Software Factory](https://insecureagents.com/live/securing-your-coding-agent): Las Vegas, NV — One prompt can fan out across fourteen repositories before you have finished your coffee, which is exactly why securing coding agents is so hard. This session explores how coding agents can operate autonomously while staying inside organizational boundaries, and the trilemma every team runs into: security, capability, and autonomy. We walk through a reference architecture from Snyk, Docker, and Keycard that lets agents run governed rather than unchecked, covering identity attribution across agent fleets instead of shared API keys, sandbox best practices like micro-VMs and default-deny networking, and supply chain security for AI-generated code. Aimed at engineers and security leaders running or overseeing coding agents. Hosted by Allie Howe during Black Hat with the Insecure Agents podcast community. - [AAuth Night Moving Beyond OAuth](https://insecureagents.com/live/aauth-night): 111 Minna Gallery, San Francisco — Authentication built for AI agents — how an agent can call resources without an API key. Lightning talks and live demos from Dick Hardt (AAuth creator, OAuth author), Jared Hanson (Keycard CTO, Passport.js author), and engineers shipping AAuth in production, closing with a panel Q&A moderated by Allie Howe. - [Building Internal AI](https://insecureagents.com/live/building-internal-ai): Dirty Habit, San Francisco — How companies deploy AI agents internally across Slack, GitHub, and Google Workspace — covering credential management, agent permissions, memory isolation, and adoption metrics. Moderated by Allie Howe with David Cramer (Sentry), Paul Klein IV (Browserbase), Brendan Irvine-Broque (Cloudflare), and Ian Livingstone (Keycard). - [Building Trustworthy Agents](https://insecureagents.com/live/live-3): Pensar, NYC — Fresh off Day 1 of swyx's AI Engineer Code Summit, our NYC community descended on Pensar's offices for a live recording of Insecure Agents, hosted by Allie Howe. Kerem Proulx (Pensar), Samuel Colvin (Pydantic), Ian Livingstone (Keycard), and Leonard Tang (Haize Labs) explored how to build AI agents people can actually trust. ## Subscribe - [Spotify](https://open.spotify.com/show/6OW0oEfrCNfZWUpBvTqYgx) - [Apple Podcasts](https://podcasts.apple.com/us/podcast/insecure-agents/id1896571149) - [Amazon Music](https://music.amazon.com/podcasts/71fe6a29-88fa-47a1-b0e7-3dbd0fbc2aa6/insecure-agents) - [YouTube Music](https://music.youtube.com/playlist?list=PLFVkWSRRR6CP7ZrzMbtLkYkCxwwQ7Ktcv&si=ZPu1zgnB3OR83wbC) - [YouTube](https://www.youtube.com/@insecure-agents) - [Substack](https://insecureagents.substack.com/) ## Follow - [X](https://x.com/insecureagents) - [Instagram](https://www.instagram.com/insecureagents) - [LinkedIn](https://www.linkedin.com/company/insecure-agents/)