Session
AI Security for Developers: Don't Give the Intern Root Access
Your AI coding assistant isn't a chatbot anymore. It clones repos, installs packages, runs commands, and wires up tools — all with your credentials. You'd never give a brand-new intern root access on day one… yet by default, that's exactly what we hand our agents.
In 45 fast, story-driven minutes we follow how real attacks actually happen: the npm heist that poisoned libraries with two billion weekly downloads, invisible malware hiding in VS Code extensions, prompt injection that quietly hijacks your agent, and booby-trapped MCP servers and CLIs. No jargon, no fear-mongering — every cinematic attack is paired with the dull, one-line "chore" that beats it: lockfiles, pinning, fencing, scanning, gates.
You'll leave able to vet a repo, a package, and an MCP before you run them, keep your agent from acting on manipulative instructions, and treat security as a habit, not a firewall. Live demos included.
Your AI coding assistant isn't a chatbot — it's a developer with tools, running commands with your credentials. This fast, story-driven session shows how attackers exploit that — supply chain, prompt injection, MCP & CLI — and the boring habits that stop them. Real breaches, live demos, zero fluff.
Jose Luis Latorre Millas
Agentic & Software Architect at Swiss Life, Microsoft AI MVP, and creator of AgentEval. I help build agentic frameworks and the validation discipline that makes AI agents & workflows reliable.
Zürich, Switzerland
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top