Securing Code You Didn't Write: The AI Era's New Threat Model
Coding agents expand the software supply chain to include repositories, configuration, comments, connectors, and tool output. Rome Thorstenson examines reported attacks and outlines practical controls for permissions, secrets, prompt injection, and defense in depth.
Chapters
- Welcome and session framing
- Talk scope and threat model
- Why Rome started Rafter
- Vibe-coded software risks
- Agents beyond autocomplete
- Untrusted input meets execution
- Supply chain risks and dependencies
- Coding agents as attack surfaces
- Poisoned agent configuration files
- Prompt injection across coding tools
- MCP and arbitrary command execution
- Expanded agent threat surface
- Vibe-coded apps and internal tools
- Defense in depth for agents
- Prompt injection beyond coding
- Practical security takeaways
- Q&A: baseline agent security
- Q&A: security checks in CI/CD
- Q&A: managing secrets safely
- Q&A: future of agent security
- Closing remarks and next session
The security boundary changes when a coding agent can read untrusted material and act with developer privileges. Rome Thorstenson maps that path across repositories, configuration files, comments, connectors, plugins, and MCP tools, using reported incidents to show how instructions can cross into execution. His practical guidance centers on reducing what an agent can read and do, keeping credentials out of chat and behind purpose-built tools, and applying defense in depth. Security feedback should also move into design, implementation, and QA rather than waiting for a final review or dependency audit.
More from the studio
1:02:51Tech TalksOperationalizing LLMs: From Prototype to Production
Yogiraj Awati shares how Instacart moves LLM applications beyond prototypes through retrieval, offline and online evaluation, guardrails, observability, and provider fallbacks. Two case studies cover recipe ingestion and Carebot support workflows with API-backed actions and human handoff.
Yogiraj Awati·Sep 17, 2026
1:17:55Tech TalksBeyond the DAG: Building Agentic Workflows That Loop, Branch, and Scale
Agentic workflows loop, branch, retry, and trigger new work instead of following a fixed DAG. Santosh Kumar Radha explains how AgentField uses typed functions, structured outputs, stopping and escalation patterns, event triggers, and controls for scaling, identity, and authorization.
Santosh Kumar Radha·Sep 17, 2026
48:04Tech TalksBuilding Trustworthy Financial AI: Governance, Bias, and Mechanistic Insights
Fabrizio Dimino examines why financial LLM recommendations can change when option order changes. He connects positional-bias tests and mechanistic interpretability with finance-specific red teaming, risk-sensitive scoring, model validation, and AI governance.
Fabrizio Dimino·Sep 17, 2026