看影片(在新分頁開啟原站)連到 AI Native Dev
摘要
探討 AI 代理(Agent)安全挑戰,揭露 76 個隱藏惡意技能案例,並說明開發者如何透過 Tessl 與 Snyk 整合掃描技能風險。看完能學到如何建立安全預設的代理環境,避免憑直覺安裝技能導致生產憑證洩漏。
This interview reveals 76 malicious AI agent skills and explains how to secure coding agents using Tessl and Snyk integration for automated scanning and governance.
摘要、重點與章節標題由語言模型整理,細節(誰說的、數字、先後)可能有誤;要引用請以原始內容為準。
重點
- 發現 76 個惡意技能,包含惡意程式碼與提示注入風險。
- Tessl 與 Snyk 整合可自動掃描技能與 MCP 伺服器風險。
- 建議開發者不要憑直覺安裝技能,應使用沙箱與信任來源。
章節
依話題轉折切分,標題由 AI 產生
- 00:00Introduction
- 01:33Chris's role: AI security incubation at Snyk
- 02:16Snyk's roots as a developer-first security company
- 03:58New security challenges from AI coding agents
- 06:26Skills: the new way to give agents context
- 07:35Inside Snyk's ToxicSkills research: malware and prompt injection
- 11:35How developers can vet skills before installing them
- 14:38A real incident: exposed production credentials at Snyk
- 17:45Building a secure-by-default agent stack
- 23:35What's next: Snyk's new coding agent security product
提到的工具與公司
- Tessl
- Snyk
- OpenClaw
- ClawHub
- Claude
- Codex
- Cursor
- Gemini
適合誰看
負責 AI 代理開發、工程安全或需要管理自動化程式碼團隊的開發者與技術主管。
摘要依據
- 依據
- 人工字幕
為什麼排在這裡
- 人氣
- 0.20
- 新鮮
- 0.75
在主題頁與搜尋結果裡,名次由相關、人氣、新鮮三個分數決定;這一頁沒有搜尋的關鍵字,所以沒有相關分數。排序怎麼算
相關內容
- BONUS: Snyk Found Malware Inside AI Agent SkillsPodcast ・ The AI Native Dev ・ 32 分鐘
- We Scanned 3,984 Skills — 1 in 7 Can Hack Your MachinePodcast ・ The AI Native Dev ・ 35 分鐘
- GitHub, Snyk, Docker & Anthropic on Securing AI Agents影片 ・ AI Native Dev ・ 10 分鐘
- 不管你用Codex 還是 Claude 都必須要知道Skills 很危險?4招肉眼排查法 + 免費神工具,秒測 Skill 安全性! |泛科學院影片 ・ 泛科學院 ・ 7 分鐘(在新分頁開啟原站)
- Sandboxing, Agent Harnesses, and Agent Teamwork影片 ・ AAIF Live ・ 1 小時 20 分
- Ask the Experts: Evaluating Agent Skills | Nemotron Labs影片 ・ NVIDIA Developer ・ 55 分鐘(在新分頁開啟原站)
摘要由 AI 根據原文產生,可能有誤;完整內容請看原站。看影片(在新分頁開啟原站)
