Snyk says agent security needs a deterministic validator, not another model
AI Engineer · youtube · 2026-07-21
Snyk's Manoj Nair argues that secure agentic development needs a deterministic validator, because the same LLM is not reliable as both generator and checker.
- In their tests, asking frontier models to find the same vulnerability five times caught it only about half the time, while a deterministic checker reached at most 75% of issues and a 40% F1 score.
- Across 4,800 customers, Snyk saw security backlog grow 108% quarter over quarter, as code generation outpaced remediation.
- A public audit of nearly 4,000 agent skills found more than one in eight had critical issues and 76 carried outright malicious payloads.
- The talk also flags MCP servers and poisoned skills as a new supply-chain risk, and shows why verification must stay outside the probabilistic loop.
Related event: Snyk: Agent Security Requires Deterministic Verification(2 posts)→
More from coding & agent
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Treating agents like 50 First Dates: a 3-layer context system so every conversation doesn't start from zero — evielync · 2026-09-11
- SmolVM open-sources persistent computer infrastructure for agents that outlive chat sessions — aniketmaurya · 2026-09-11
- ARRM targets silent economic regressions in AI agents that functional tests miss — Beautiful_Belt_601 · 2026-09-11
- Dev builds browser 3D pizza delivery game with Claude: physics, GPS pathfinding, traffic AI — vinishkapoor · 2026-09-11
- Build X Carousel Posts from One Wide Image: A Splitter Tool Plus YouMind Skill Workflow — sujingshen · 2026-09-11