Data Becomes Code | Episode 68
What happens when AI coding agents treat vendor documentation as trusted instructions? Bronwen Aker and Derek Banks examine research showing how unclaimed package names and domains referenced in LLMs.txt files could lead coding agents to download and execute unintended code. They discuss how this AI-driven supply chain risk builds on familiar security problems, including dependency confusion, indirect prompt injection, and excessive permissions. The conversation also covers responsibility for AI-generated code, OpenAI’s cybersecurity proposals, and practical protections such as sandboxing, containerization, least privilege, network monitoring, and human oversight.
LINK: Data Became Code: AI Agents Installed Unowned Packages Inside Fortune 500s
Click here to watch this episode on YouTube.
Brought to you by:
LINK: Data Became Code: AI Agents Installed Unowned Packages Inside Fortune 500s
- (00:00) - Welcome to AI Security Ops Podcast
- (00:59) - AI Agents Install Unclaimed Software Packages
- (02:33) - How LLMs.txt Creates a New Supply Chain Risk
- (04:47) - Coding Agents Trust and Execute Vendor Documentation
- (07:35) - Who Owns and Secures AI-Generated Code?
- (08:18) - Prompt Injection, Sandboxing, and Containerization
- (11:40) - Where Did the Malicious References Come From?
- (13:38) - Reviewing OpenAI’s Cybersecurity Proposals
- (17:23) - Making Cyber Defense a Leadership Priority
- (19:06) - Practical Security Controls for Coding Agents
- (21:49) - When Data Becomes Code
- (22:33) - Closing Thoughts
Click here to watch this episode on YouTube.
Brought to you by:
Black Hills Information Security
☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/
Antisyphon Training
Active Countermeasures
Wild West Hackin Fest
Episode Video
Creators and Guests
Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Host
Derek Banks
Derek is a BHIS Security Consultant, Penetration Tester, and Red Teamer with advanced degrees, industry certifications, and broad experience across forensics, incident response, monitoring, and offensive security, who enjoys learning from colleagues, helping clients improve their security, and spending his free time with family, fitness, and playing bass guitar.