Snyk says agent security needs a deterministic validator, not another model

AI Engineer · youtube · 2026-07-21

Snyk's Manoj Nair argues that secure agentic development needs a deterministic validator, because the same LLM is not reliable as both generator and checker. - In their tests, asking frontier models to find the same vulnerability five times caught it only about half the time, while a deterministic checker reached at most **75%** of issues and a **40% F1** score. - Across **4,800 customers**, Snyk saw security backlog grow **108% quarter over quarter**, as code generation outpaced remediation. - A public audit of nearly **4,000 agent skills** found more than **one in eight** had critical issues and **76** carried outright malicious payloads. - The talk also flags MCP servers and poisoned skills as a new supply-chain risk, and shows why verification must stay outside the probabilistic loop.

Related event: Snyk: Agent Security Requires Deterministic Verification(2 posts)→

Original post →

More from coding & agent

coding & agent channel →