跳到主要內容
AI 武林
影片進階EN290 次觀看

BONUS EPISODE: 76 Malicious AI Skills Were Hiding in Plain Sight

來源 AI Native Dev

看影片(在新分頁開啟原站)連到 AI Native Dev

摘要

探討 AI 代理(Agent)安全挑戰,揭露 76 個隱藏惡意技能案例,並說明開發者如何透過 Tessl 與 Snyk 整合掃描技能風險。看完能學到如何建立安全預設的代理環境,避免憑直覺安裝技能導致生產憑證洩漏。

This interview reveals 76 malicious AI agent skills and explains how to secure coding agents using Tessl and Snyk integration for automated scanning and governance.

摘要、重點與章節標題由語言模型整理,細節(誰說的、數字、先後)可能有誤;要引用請以原始內容為準。

重點

  • 發現 76 個惡意技能,包含惡意程式碼與提示注入風險。
  • Tessl 與 Snyk 整合可自動掃描技能與 MCP 伺服器風險。
  • 建議開發者不要憑直覺安裝技能,應使用沙箱與信任來源。

章節

依話題轉折切分,標題由 AI 產生

  1. 00:00Introduction
  2. 01:33Chris's role: AI security incubation at Snyk
  3. 02:16Snyk's roots as a developer-first security company
  4. 03:58New security challenges from AI coding agents
  5. 06:26Skills: the new way to give agents context
  6. 07:35Inside Snyk's ToxicSkills research: malware and prompt injection
  7. 11:35How developers can vet skills before installing them
  8. 14:38A real incident: exposed production credentials at Snyk
  9. 17:45Building a secure-by-default agent stack
  10. 23:35What's next: Snyk's new coding agent security product

提到的工具與公司

  • Tessl
  • Snyk
  • OpenClaw
  • ClawHub
  • Claude
  • Codex
  • Cursor
  • Gemini

適合誰看

負責 AI 代理開發、工程安全或需要管理自動化程式碼團隊的開發者與技術主管。

摘要依據

依據
人工字幕

為什麼排在這裡

人氣
0.20
新鮮
0.75

在主題頁與搜尋結果裡,名次由相關、人氣、新鮮三個分數決定;這一頁沒有搜尋的關鍵字,所以沒有相關分數。排序怎麼算

摘要由 AI 根據原文產生,可能有誤;完整內容請看原站。看影片(在新分頁開啟原站)