Securing Your Coding Agent: The Road to the Software Factory

Securing Your Coding Agent: The Road to the Software Factory

Om arrangementet

Your coding agent has more access than you think. It operates with your credentials, your .env file, and reached into every repository that the host can touch. When it ships code, that code goes out faster than anyone can review it.

Everyone's talking about the software factory: agents running loops and shipping code unattended while you sleep. The factory demands three things at once: security, capability, and autonomy. However, most teams face impossible trade-offs that hinder them from achieving all three. Locking the agent down kills its capability and autonomy; that's what consent fatigue really is—clicking 'yes' on autopilot without reading. Unleash it, and you've handed long-lived secrets to a process you can't attribute or halt.

This trilemma is a false choice. There’s an architecture that grants an agent real autonomy within a governed boundary. Securing the coding agent turns out to be the prerequisite for the factory, not an afterthought.

At Black Hat, Insecure Agents is hosting a panel discussing best practices for securing your coding agent, featuring a new reference architecture from Snyk, Docker, and Keycard. This architecture provides a single governed boundary for every agentic action, spanning from identity to sandbox to supply chain.

  • Keycard: Issues short-lived, resource-scoped credentials that the agent never holds, binding every action back to a human principal.
  • Docker: Offers throwaway micro-VM sandboxes with default-deny egress, ensuring a runaway agent has nowhere to reach.
  • Snyk: Provides software verification and protects your software supply chain.

Moderated by Allie Howe, host of the Insecure Agents Podcast.

What We'll Discuss:

  • The security, capability, autonomy trilemma and how to prevent it from becoming a two-out-of-three choice.
  • Why sharing one API key across your agent fleet undermines attribution and what per-action identity looks like instead.
  • Sandboxing best practices: micro-VMs, default-deny networking, and credentials the agent never sees.
  • Securing the agent supply chain, from AI-BOMs to the code your agent has just written.

Who Should Attend: Engineers and security leads using or governing coding agents, seeking to run them without concern.

📍 Location: Marquee Nightclub, 3708 S Las Vegas Blvd, Las Vegas, NV 89109, USA
🎟️ Get your tickets here!

Funnet av Somo·Se original
Sted

Marquee Nightclub, 3708 S Las Vegas Blvd, Las Vegas, NV 89109, USA

Veibeskrivelse

Denne uken i Sverige