
Agents with commit and system access need a security posture most teams have not designed yet.
“The most common failure mode in current AI deployments is a lack of access control to the agent. We discovered multiple agents that held credentials for individual users and were accessible to any authorized user within the internal network.”
Michelle Horton
“An attacker who can write content to system files such as ~/.bashrc or ~/.zshrc , or configuration files such as ~/.gitconfig , hooks.json , MCP.json , or skills files, can achieve code execution when a different process executes the relevant file, even if command-line execution is not directly available”
Michelle Horton
“When an agent with command execution shares that environment, inducing it to run env , printenv , or /proc/self/environ enables direct inspection of them.”
Michelle Horton
“A consistent finding is that defenses in the same control plane as the LLM, particularly prompt-based defenses, are routinely subverted. Controls must be enforced outside of the model’s control plane.”
Michelle Horton
“Prompt-based guardrails, including the LLM-as-a-judge pattern, do not close any of these gaps. Architectural controls do: access control to the agent, hardened sandboxes with least-privilege access to enterprise data, default-deny network egress controls, and secrets kept out of the agent’s reach.”
Michelle Horton
articleRun NVIDIA BioNeMo NIM Microservices for Protein Structure Prediction in Claude Science
articleSolving Agentic AI Fleet Challenges with NVIDIA Vera CPUChecking sign-in…
Loading comments…