<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Agentic Security: Permissions, Provenance, and the Agent Supply Chain — Steve Yegge, Gas Town</title>
        <link>https://video.ut0pia.org/videos/watch/e9a370d2-f4f1-443c-844f-c9475e4382c7</link>
        <description>A security hardening pass by Fable over a game one engineer had built for 30 years came back clean: cloud hardening done, credentials handled, good vibes all around. Then Snyk ran over the same code and surfaced 241 vulnerabilities the agent never thought to look for. That gap is the center of Steve Yegge's talk, whose real title, he says, is not agentic security but be scared. A chief security architect at a big bank had already handed him the math: if everyone ships code 10 times faster and the rate of security defects holds steady, the vulnerable surface grows 10 times with it, and with models writing the code that rate does not hold steady, it gets worse. The frightening part is not the familiar bugs like XSS that models still cheerfully write, it is the new attack surface. Slop squatting is the clean example: a model hallucinates a package name like graphy 123, someone uploads a real package under that exact name that does the expected thing plus a backdoor, and the build succeeds with the tests green. Yegge's partial answer follows from how models work. They do one thing well at a time, so asking for correctness and security in a single pass gets you a half job of both. Security becomes its own pass, the first one and the last one, with the agent handed real tools like Snyk and Chainguard to check its own work. And the window is closing: Five Eyes now measures the moment open source models can autonomously hack production systems in months, not years. Speaker info: https://www.linkedin.com/in/steveyegge, https://x.com/steve_yegge, https://github.com/steveyegge/beads, Timestamps: 0:00 - The real title of this talk: be scared 1:38 - The bank architect's question: 10x speed, 10x defect surface 3:08 - New attack surfaces and slop squatting 4:51 - How Google surfaces bugs at the developer's fingertips 6:08 - Why security bugs have no half life 6:46 - Can the model just write secure code? 7:24 - Running Snyk on his own game: 241 vulnerabilities 8:14 - The rule of five and security as its own pass 9:32 - Software Survival 3.0: lazy models reach for tools 10:09 - Give the agent Snyk and Chainguard 12:03 - Five Eyes: months, not years 13:34 - Refresh your family code words 14:36 - The arms race you can start fighting now 15:30 - Q&amp;A: what has surprised you in AI coding 17:28 - Q&amp;A: Gas Town, beads, and running agents all night 19:13 - Q&amp;A: adversarial agents watching your agents 20:58 - Q&amp;A: prompt injection</description>
        <lastBuildDate>Tue, 21 Jul 2026 19:34:31 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://video.ut0pia.org</generator>
        <image>
            <title>Agentic Security: Permissions, Provenance, and the Agent Supply Chain — Steve Yegge, Gas Town</title>
            <url>https://video.ut0pia.org/lazy-static/avatars/0287a09a-aae7-4840-9843-b416426e7046.webp</url>
            <link>https://video.ut0pia.org/videos/watch/e9a370d2-f4f1-443c-844f-c9475e4382c7</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://video.ut0pia.org/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://video.ut0pia.org/feeds/video-comments.xml?videoId=e9a370d2-f4f1-443c-844f-c9475e4382c7" rel="self" type="application/rss+xml"/>
    </channel>
</rss>