It shows that giving agents shell access creates prompt-injection risk from combinations of individually innocuous permissions that code review misses, and describes a deterministic YARA-based scanner built in response, after sub-agents were caught inventing ways around .
videoAgents Without Code: Skills, YAML, and Filesystems Replaced Python — Philipp Schmid, Google DeepMind
videoNo Memory, No Harness: Why the Database Is the Last Line of Defense — Kay Malcolm, Oracle
videoHow We Solved Agent Building — Andrew Qu, Vercel
videoEvery step you take, every call you make: the reliable agent stack — Giselle van Dongen, RestateChecking sign-in…
Loading comments…