Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk
Manoj Nair from Snyk argues that the fundamental architectural decision for agentic security is separating the generator and validator, as LLMs alone cannot reliably validate security outputs. He presents real-world data showing that autonomous attacks are real, code quality from AI is worsening, and agent behavior (e.g., copying PII) creates unknown attack surfaces. Snyk offers tools like package health checks, skill risk assessment, and Agentic Dev Security to prevent, detect, and remediate these issues, but emphasizes that the industry must collaborate on open security engineering.