Agentic Security: Permissions, Provenance, and the Agent Supply Chain — Steve Yegge, Gas Town

Agentic Security: Permissions, Provenance, and the Agent Supply Chain — Steve Yegge, Gas Town

More

Descriptions:

Steve Yegge, presenting on behalf of Snyk at the AI Engineer conference, delivers an urgent warning about the security surface that AI-assisted development is creating. His central argument: if coding agents ship code ten times faster while the defect rate stays constant — or worsens — the total vulnerability surface scales proportionally. A question from a chief security architect at a major bank crystallized this for him: the implied threat isn’t just more of the same bugs, it’s a new class of vulnerabilities that nobody yet knows how to detect at scale.

Yegge introduces the concept of “slop squatting” — a novel attack where bad actors register package names that LLMs habitually hallucinate, uploading backdoored packages that build, test, and run correctly while containing hidden vulnerabilities. He argues this and similar supply chain vectors are already live and well-polished. He also references a Five Eyes advisory warning that dangerous open-source model capability thresholds are now “months, not years” away.

His partial solution is to integrate tools like Snyk and ChainGuard directly into agent prompts, so LLMs run security analysis as part of every code generation pass rather than leaving it to downstream human review. Yegge frames this as giving LLMs a security superpower — and argues it is the only approach that can scale with the speed at which agents now produce code.


📺 Source: AI Engineer · Published July 20, 2026
🏷️ Format: Keynote Launch

1 Item

Channels