Skip to content
Artwork for AI Security Ops
AI Security Ops · Yesterday · 23 min

Data Becomes Code | Episode 68

What happens when AI coding agents treat vendor documentation as trusted instructions? Bronwen Aker and Derek Banks examine research showing how unclaimed package names and domains referenced in LLMs.txt files could lead coding agents to download and execute unintended code. They discuss how this AI-driven supply chain risk builds on familiar security problems, including dependency confusion, indirect prompt injection, and excessive permissions. The conversation also covers responsibility for AI-generated code, OpenAI’s cybersecurity proposals, and practical protections such as sandboxing, containerization, least privilege, network monitoring, and human oversight. LINK: Data Became Code: AI Agents Installed Unowned Packages Inside Fortune 500s (00:00) - Welcome to AI Security Ops Podcast (00:59) - AI Agents Install Unclaimed Software Packages (02:33) - How LLMs.txt Creates a New Supply Chain Risk (04:47) - Coding Agents Trust and Execute Vendor Documentation (07:35) - Who Owns and Secures AI-Generated Code? (08:18) - Prompt Injection, Sandboxing, and Containerization (11:40) - Where Did the Malicious References Come From? (13:38) - Reviewing OpenAI’s Cybersecurity Proposals (17:23) - Making Cyber Defense a Leadership Priority (19:06) - Practical Security Controls for Coding Agents (21:49) - When Data Becomes Code (22:33) - Closing Thoughts Click here to watch this episode on YouTube. Creators & Guests Derek Banks - Host Bronwen Aker - Host Brought to you by: Black Hills Information Security https://www.blackhillsinfosec.com ☯️ Introducing BHIS Fusion Penetration Testing https://www.blackhillsinfosec.com/fusion-penetration-testing/ Antisyphon Training https://www.antisyphontraining.com/ Active Countermeasures https://www.activecountermeasures.com Wild West Hackin Fest https://wildwesthackinfest.com 🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com Click here to view the episode transcript.

0:00 · Welcome to AI Security Ops Podcast-23:19

transcript

No transcript — this publisher did not publish one.

show notes

What happens when AI coding agents treat vendor documentation as trusted instructions? Bronwen Aker and Derek Banks examine research showing how unclaimed package names and domains referenced in LLMs.txt files could lead coding agents to download and execute unintended code. They discuss how this AI-driven supply chain risk builds on familiar security problems, including dependency confusion, indirect prompt injection, and excessive permissions. The conversation also covers responsibility for AI-generated code, OpenAI’s cybersecurity proposals, and practical protections such as sandboxing, containerization, least privilege, network monitoring, and human oversight.

LINK: Data Became Code: AI Agents Installed Unowned Packages Inside Fortune 500s


  • (00:00) - Welcome to AI Security Ops Podcast
  • (00:59) - AI Agents Install Unclaimed Software Packages
  • (02:33) - How LLMs.txt Creates a New Supply Chain Risk
  • (04:47) - Coding Agents Trust and Execute Vendor Documentation
  • (07:35) - Who Owns and Secures AI-Generated Code?
  • (08:18) - Prompt Injection, Sandboxing, and Containerization
  • (11:40) - Where Did the Malicious References Come From?
  • (13:38) - Reviewing OpenAI’s Cybersecurity Proposals
  • (17:23) - Making Cyber Defense a Leadership Priority
  • (19:06) - Practical Security Controls for Coding Agents
  • (21:49) - When Data Becomes Code
  • (22:33) - Closing Thoughts

Click here to watch this episode on YouTube.

Creators & Guests

Brought to you by:

Black Hills Information Security 

https://www.blackhillsinfosec.com


☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training

https://www.antisyphontraining.com/


Active Countermeasures

https://www.activecountermeasures.com


Wild West Hackin Fest

https://wildwesthackinfest.com

🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
https://poweredbybhis.com

Click here to view the episode transcript.

links11

chapters

12 chapters