One Snyk developer's AI skill quietly handed their coding agent production credentials, and the security team found out the hard way. Krzysztof Huszcza, who leads AI security incubation at Snyk, joins this special Tessl and Snyk live stream to unpack the ToxicSkills research that uncovered 76 malicious agent skills in the wild, and what it actually takes to run coding agents safely at scale.
What we cover: – How Snyk's security team found 76 malicious skills hiding inside a popular open agent skill repository – Why skills have become the go-to way developers hand context to their coding agents – The internal incident at Snyk where a developer's skill exposed production credentials to an agent – How the Tessl and Snyk integration scans every skill and MCP server for risk before you install it – What's coming next with Snyk's new Evo product for governing coding agents at scale
Chapters: 00:00:00 - Introduction 00:01:33 - Chris's role: AI security incubation at Snyk 00:02:16 - Snyk's roots as a developer-first security company 00:03:58 - New security challenges from AI coding agents 00:06:26 - Skills: the new way to give agents context 00:07:35 - Inside Snyk's ToxicSkills research: malware and prompt injection 00:11:35 - How developers can vet skills before installing them 00:14:38 - A real incident: exposed production credentials at Snyk 00:17:45 - Building a secure-by-default agent stack 00:23:35 - What's next: Snyk's new coding agent security product
🌐 Tessl: https://tessl.io 🔔 Subscribe for weekly episodes on AI-native development
What's the riskiest skill you've installed without checking it first? Let us know in the comments.
Podden och tillhörande omslagsbild på den här sidan tillhör
Tessl. Innehållet i podden är skapat av Tessl och inte av,
eller tillsammans med, Poddtoppen.