Snyk workshop: AI bills of materials, MCP tool poisoning and layered LLM defenses

AI Engineer · youtube · 2026-10-12

Snyk's Javier Garza delivers an AI security engineer workshop covering: AI bills of materials via CLI scan to searchable inventory of models/datasets/agents; OWASP LLM risks demonstrated with Gandalf and indirect prompt injection; layered defenses (database views, least privilege, output validation, human approval); threat modeling with MITRE ATLAS; securing agent skills and MCP servers by separating tool-definition scans (hidden instructions/tool poisoning in SKILL.md) from code scans, with a scan-fix-rescan loop via coding agent hooks; plus a deliberately vulnerable practice app.

Original post →

More from coding & agent

coding & agent channel →