Snyk workshop: AI bills of materials, MCP tool poisoning and layered LLM defenses
AI Engineer · youtube · 2026-10-12
Snyk's Javier Garza delivers an AI security engineer workshop covering: AI bills of materials via CLI scan to searchable inventory of models/datasets/agents; OWASP LLM risks demonstrated with Gandalf and indirect prompt injection; layered defenses (database views, least privilege, output validation, human approval); threat modeling with MITRE ATLAS; securing agent skills and MCP servers by separating tool-definition scans (hidden instructions/tool poisoning in SKILL.md) from code scans, with a scan-fix-rescan loop via coding agent hooks; plus a deliberately vulnerable practice app.
More from coding & agent
- DeepSeek-V4.1-Flash on 2x DGX Spark: TP2 Patches Cut First Token From 33.8s to 4.9s — rez0__ · 2026-10-12
- Running Two AI Agents on Raspberry Pis with Full Sudo, RTL-SDRs and Starlink — natesiggard · 2026-10-12
- Indie Dev Builds Kids' Book Store Almost Entirely With an AI Agent — ConstructionIcy5855 · 2026-10-12
- mitsuhiko: No one-size-fits-all sandbox for agents — VMs, sandboxes, durable objects each have their place — mitsuhiko · 2026-10-12
- After days of testing, dev ditches sol 6.1 and astra 6 for agentic work, returns to Opus — NERDDISCO · 2026-10-12
- PhD student uses nightly Grok agent to auto-fill Zotero with papers and open-access PDFs — Scobleizer · 2026-10-12