← Back
AI Engineer October 10, 2026 20m

The Lethal Trifecta Is Already on Your Laptops — Michael Patterson, Coder

Read full transcript 17 segments
  1. How is everyone doing? Steeply. It's a pleasure Steeply. It's a pleasure to perform in front of you. to perform in front of you. to perform in front of you. I hope you're having a great I hope you're having a great I hope you're having a great time here at the time here at the time here at the AI ​​Dev conference, the AI ​​Dev conference, the AI ​​Dev conference, the AI AI engineering conference. My name is engineering conference. My name is engineering conference. My name is Michael Patterson. I am a Michael Patterson. I am a Michael Patterson. I am a lead lead lead solutions engineer at Coda. Today solutions engineer at Coda. Today solutions engineer at Coda. Today I want to talk about the " I want to talk about the " deadly trio". There are deadly trio". There are deadly trio". There are few of us here. Can few of us here. Can few of us here. Can I see the I see the I see the hands raised? Has anyone heard of the " hands raised? Has anyone heard of the " deadly trio"? All of deadly trio"? All of deadly trio"? All of us or half of us. us or half of us. us or half of us. So, it's about 50/50 So, it's about 50/50 . Fantastically. I'll talk a little . Fantastically. I'll talk a little . Fantastically. I'll talk a little about what it is about what it is about what it is and how we at Coda and how we at Coda and how we at Coda learned to work with it learned to work with it learned to work with it . To . To . To begin, I'll remove these begin, I'll remove these begin, I'll remove these notes from the notes from the notes from the presenter's screen. Sorry. presenter's screen. Sorry. I want to start with a I want to start with a brief overview of brief overview of brief overview of agent-based AI in 2025 agent-based AI in 2025 agent-based AI in 2025 . 2025 has . 2025 has . 2025 has undoubtedly become the undoubtedly become the undoubtedly become the year of AI agents.

  2. year of AI agents. year of AI agents. Everyone had a new Everyone had a new Everyone had a new agent tool: agent tool: agent tool: Microsoft, Salesforce, AWS, and Claude Microsoft, Salesforce, AWS, and Claude Microsoft, Salesforce, AWS, and Claude Code was a Code was a Code was a game changer after its release in game changer after its release in game changer after its release in March. Everyone March. Everyone March. Everyone used these used these used these technologies. I have a technologies. I have a technologies. I have a short story. “Vibe short story. “Vibe short story. “Vibe coding” was a really coding” was a really coding” was a really big deal. big deal. Jason wrote on Jason wrote on Twitter how agent Twitter how agent Twitter how agent programming programming programming changed his life. changed his life. He wrote a lot of code, He wrote a lot of code, made a lot of changes to made a lot of changes to made a lot of changes to his product. This was his product. This was his product. This was his future. And his future. And his future. And then, less than a then, less than a then, less than a day or two later, he day or two later, he day or two later, he writes again on Twitter: " writes again on Twitter: " Agent AI just Agent AI just Agent AI just destroyed my product, destroyed my product, destroyed my product, deleted the deleted the deleted the production database. "How production database. "How production database. "How can you even can you even can you even use use use such AI?" Ahem. The thing is such AI?" Ahem. The thing is such AI?" Ahem. The thing is that AI agents are very that AI agents are very that AI agents are very powerful, but powerful, but powerful, but they create problems. Is they create problems. Is everyone familiar with Open Claw?

  3. Truth? So what's wrong with Truth? So what's wrong with Open Claw? This is a very cool Open Claw? This is a very cool Open Claw? This is a very cool tool. You tool. You tool. You install your own install your own install your own AI on your computer, it AI on your computer, it AI on your computer, it becomes your personal becomes your personal becomes your personal assistant and does assistant and does assistant and does many wonderful things. many wonderful things. But you've probably But you've probably seen everyone say, seen everyone say, seen everyone say, "If you're "If you're "If you're using Open Claw, using Open Claw, using Open Claw, it's better to buy a Mac Mini and it's better to buy a Mac Mini and it's better to buy a Mac Mini and install it install it install it separately from your separately from your separately from your main computer, main computer, main computer, right?" Because it right?" Because it right?" Because it has has has security vulnerabilities. The worst that security vulnerabilities. The worst that security vulnerabilities. The worst that can happen is that Open Claw can happen is that Open Claw can happen is that Open Claw will download your will download your will download your confidential files, confidential files, confidential files, upload them to the Internet upload them to the Internet , download viruses, and , download viruses, and , download viruses, and delete your delete your delete your personal data so that personal data so that personal data so that you don't have it anymore, you don't have it anymore, you don't have it anymore, and the rest of the world and the rest of the world and the rest of the world gets it. So there are gets it. So there are gets it. So there are a lot of problems with a lot of problems with a lot of problems with agents that we're still agents that we're still agents that we're still trying to understand trying to understand , as well as how to , as well as how to , as well as how to develop develop develop AI agents safely. Today I'm AI agents safely. Today I'm AI agents safely. Today I'm going to spend some time on the " going to spend some time on the " deadly deadly deadly triumvirate," if you have triumvirate," if you have triumvirate," if you have n't heard of it, and n't heard of it, and n't heard of it, and how Coder is addressing how Coder is addressing how Coder is addressing the principles of agent the principles of agent the principles of agent security and how people security and how people security and how people are turning to us are turning to us are turning to us to solve these to solve these to solve these problems and problems and problems and scale AI in scale AI in scale AI in their companies. So their companies. So , a little about Coder.

  4. , a little about Coder. , a little about Coder. Coder was Coder was Coder was founded in 2017. founded in 2017. It was founded by three It was founded by three teenagers who teenagers who teenagers who were creating mods for were creating mods for were creating mods for Minecraft and were tired of Minecraft and were tired of Minecraft and were tired of constantly constantly constantly setting up setting up setting up virtual machines virtual machines virtual machines to develop these to develop these to develop these mods. Somehow mods. Somehow mods. Somehow they created they created they created a company worth a company worth a company worth $80 million. We are $80 million. We are $80 million. We are very proud of them. very proud of them. Coder provides a Coder provides a stable, reliable, and stable, reliable, and stable, reliable, and secure remote secure remote secure remote development environment. development environment. These environments can be These environments can be deployed almost deployed almost deployed almost anywhere. They anywhere. They anywhere. They are configured are configured are configured using Terraform. We are using Terraform. We are open source. We are not dependent open source. We are not dependent open source. We are not dependent on specific on specific on specific models. We are not models. We are not models. We are not dependent on cloud dependent on cloud dependent on cloud platforms. You can platforms. You can platforms. You can host this host this host this locally, and we locally, and we locally, and we think it's a think it's a think it's a great solution if great solution if great solution if you need a you need a you need a self-hosted self-hosted self-hosted model for your model for your model for your development or development or development or agent environments. We are agent environments. We are agent environments. We are trusted by some of the trusted by some of the trusted by some of the largest companies largest companies largest companies in the US and Europe. Here are in the US and Europe. Here are in the US and Europe. Here are some of the famous names of some of the famous names of some of the famous names of our clients. We our clients. We our clients. We work with, I think, work with, I think, work with, I think, six of the ten six of the ten six of the ten largest banks, largest banks, largest banks, many hedge many hedge funds, and government funds, and government funds, and government agencies. Essentially, agencies. Essentially, agencies. Essentially, if the SaaS model doesn't if the SaaS model doesn't if the SaaS model doesn't suit you, if you suit you, if you suit you, if you have on-premises have on-premises have on-premises infrastructure, and you infrastructure, and you infrastructure, and you don't want code don't want code don't want code stored on a stored on a stored on a developer's laptop developer's laptop developer's laptop or outside your or outside your or outside your control, Coder control, Coder control, Coder is usually a good is usually a good is usually a good solution. So, what

  5. solution. So, what solution. So, what is the "deadly is the "deadly is the "deadly triumvirate"? This triumvirate"? This triumvirate"? This term was coined by Simon term was coined by Simon term was coined by Simon Ellison; Essentially, these are Ellison; Essentially, these are Ellison; Essentially, these are three levels of three levels of three levels of attack surface threats. attack surface threats. First: if your First: if your agent is on a agent is on a agent is on a laptop, it could laptop, it could laptop, it could be Claw Code, Open Claw, Codex, be Claw Code, Open Claw, Codex, be Claw Code, Open Claw, Codex, etc. This laptop has etc. This laptop has etc. This laptop has access to private access to private access to private data. This could be data. This could be data. This could be personal information, personal information, personal information, computer files, computer files, computer files, credentials, credentials, company intellectual property, company intellectual property, or databases. Now or databases. Now or databases. Now your laptop has your laptop has your laptop has access to this. Your access to this. Your access to this. Your agent now also has agent now also has agent now also has access to this access to this access to this private data. private data. With access to this With access to this private data, he private data, he private data, he can also can also can also transmit it to the transmit it to the transmit it to the internet. Right? internet. Right? internet. Right? So, he has access So, he has access So, he has access to private data and to private data and to private data and can post it on the can post it on the can post it on the Internet. And he can Internet. And he can Internet. And he can not only post this not only post this not only post this data on the Internet, but also data on the Internet, but also data on the Internet, but also download download download anything from there. So, this is a anything from there. So, this is a anything from there. So, this is a problem because problem because problem because you have no control you have no control you have no control over what exactly the over what exactly the over what exactly the agent can do when agent can do when agent can do when you give it a request you give it a request . So one of these . So one of these . So one of these three factors is not that three factors is not that three factors is not that big of a big of a big of a problem. But two out of problem. But two out of problem. But two out of three is absolutely three is absolutely three is absolutely unacceptable in unacceptable in any secure any secure any secure corporate corporate corporate environment.

  6. environment. environment. The presence of all three The presence of all three The presence of all three is, in fact, is, in fact, is, in fact, unacceptable. unacceptable. unacceptable. The question is not whether a The question is not whether a security incident will occur due to an agent security incident will occur due to an agent on your laptop, but on your laptop, but on your laptop, but when it will when it will when it will happen. So, here are happen. So, here are happen. So, here are some some some attack scenarios. I'm sure attack scenarios. I'm sure attack scenarios. I'm sure everyone here has heard of everyone here has heard of prompt injection—it's essentially the presence of malicious presence of malicious presence of malicious instructions in an instructions in an instructions in an information source that an information source that an information source that an agent trusts. He agent trusts. He agent trusts. He can view can view error messages, error messages, support tickets, or support tickets, or support tickets, or CICD logs. It's CICD logs. It's very easy for an attacker very easy for an attacker to add something to to add something to to add something to any of these any of these any of these messages, and the agent messages, and the agent messages, and the agent will simply take it as will simply take it as will simply take it as truth and do something truth and do something truth and do something you didn't you didn't you didn't expect them to do. Context poisoning expect them to do. Context poisoning lies in the same lies in the same plane: you are actually plane: you are actually plane: you are actually introducing false introducing false introducing false information into the information into the information into the documentation, data— documentation, data— everywhere your everywhere your everywhere your agent will collect agent will collect agent will collect information from. And if there information from. And if there information from. And if there 's any malicious 's any malicious 's any malicious data there, the agent will simply data there, the agent will simply data there, the agent will simply take it and take it and take it and do whatever it do whatever it do whatever it wants. And there's also wants. And there's also wants. And there's also privilege escalation privilege escalation , right? Everyone is familiar with the , right? Everyone is familiar with the , right? Everyone is familiar with the principle of least principle of least principle of least privilege, right?

  7. privilege, right? We usually give We usually give agents access agents access agents access to almost everything because to almost everything because to almost everything because they need that they need that they need that access to do their access to do their access to do their job, right? job, right? job, right? So any of these So any of these So any of these query injections or query injections or query injections or context poisonings context poisonings context poisonings can inadvertently can inadvertently can inadvertently elevate elevate elevate an agent's privileges, allowing it to an agent's privileges, allowing it to an agent's privileges, allowing it to do things it do things it do things it shouldn't: shouldn't: shouldn't: delete tables, delete tables, delete tables, upload files, upload files, upload files, make queries, or make queries, or make queries, or publish things publish things publish things it's not allowed to. So it's not allowed to. So it's not allowed to. So how do we fix this? how do we fix this? There are three pillars to There are three pillars to this deadly this deadly this deadly trio. There are three pillars of trio. There are three pillars of trio. There are three pillars of agent security. We agent security. We agent security. We call this the call this the call this the agent security trio. agent security trio. First, you must First, you must First, you must control access control access control access to the data. If you to the data. If you to the data. If you are going to are going to are going to use use use an agent, don't keep an agent, don't keep an agent, don't keep it on your it on your it on your laptop, rather laptop, rather laptop, rather place it in a place it in a place it in a secure, preferably secure, preferably secure, preferably virtual, virtual, virtual, environment. This will environment. This will environment. This will block access to block access to block access to private files and private files and private files and prevent destructive prevent destructive prevent destructive actions on your machine, actions on your machine, actions on your machine, as the agent as the agent as the agent will be running on a different will be running on a different will be running on a different system. Then you should system. Then you should system. Then you should limit external limit external limit external communications. If you communications. If you communications. If you place the agent on place the agent on place the agent on some server or some server or some server or virtual machine, virtual machine, virtual machine, it will be it will be it will be architecturally architecturally architecturally isolated from isolated from isolated from your network. It will your network. It will only be able to access domains that only be able to access domains that you have granted permission to you have granted permission to . This will be in your VPN, . This will be in your VPN, . This will be in your VPN, your VPC, this your VPC, this your VPC, this will go through the will go through the will go through the firewall, and then firewall, and then firewall, and then any traffic any traffic any traffic that this that this that this agent creates on this machine agent creates on this machine agent creates on this machine will be controlled.

  8. will be controlled. You will be able to see everything it does, and if does, and if does, and if it ever violates it ever violates it ever violates that perimeter, you that perimeter, you that perimeter, you should have a way to should have a way to should have a way to alert alert alert administrators or administrators or administrators or yourself that the agent is yourself that the agent is yourself that the agent is going where it shouldn't so going where it shouldn't so you can you can you can effectively shut down effectively shut down effectively shut down that virtual machine that virtual machine that virtual machine or agent. And you also or agent. And you also or agent. And you also need to limit need to limit need to limit content, contacts, and content, contacts, and content, contacts, and access. So, you access. So, you access. So, you want to restrict want to restrict want to restrict permissions, limit the permissions, limit the permissions, limit the access it has, access it has, access it has, and use and use and use strictly defined strictly defined strictly defined credentials. The point is credentials. The point is credentials. The point is , , , agent security is no agent security is no agent security is no different than different than different than sound sound sound security practices for anyone security practices for anyone security practices for anyone else, right? And we else, right? And we else, right? And we think that because think that because think that because AI is so powerful, we AI is so powerful, we AI is so powerful, we can just give can just give can just give it everything it needs, it everything it needs, it everything it needs, and it won't and it won't and it won't make the same make the same make the same mistakes and mistakes and mistakes and won't be vulnerable to the won't be vulnerable to the won't be vulnerable to the same threats as a same threats as a same threats as a human. So we human. So we human. So we want to make sure want to make sure want to make sure that we isolate this that we isolate this that we isolate this machine, secure machine, secure machine, secure the environment, and the environment, and the environment, and intercept intercept any communication that this any communication that this any communication that this agent might agent might agent might make with the wider make with the wider make with the wider internet. So I'll internet. So I'll internet. So I'll quickly walk through what quickly walk through what deploying agents deploying agents at scale looks like in at scale looks like in at scale looks like in very, very large very, very large very, very large companies. What companies. What companies. What are the barriers are the barriers are the barriers to implementation?

  9. to implementation? to implementation? Why don't companies Why don't companies Why don't companies want to do this? want to do this? want to do this? What challenges What challenges What challenges arise if you arise if you arise if you decide to implement decide to implement decide to implement agent-based AI in your agent-based AI in your agent-based AI in your company? And what company? And what company? And what questions can you questions can you questions can you expect if you're expect if you're expect if you're trying to lead an trying to lead an AI initiative in AI initiative in your company. So, your company. So, your company. So, what challenges can we what challenges can we what challenges can we expect? expect? expect? You You You actually need actually need actually need security approval security approval security approval from the CISO before implementation. You from the CISO before implementation. You from the CISO before implementation. You need need need DevOps support because they are the ones who have to DevOps support because they are the ones who have to DevOps support because they are the ones who have to deploy deploy deploy this for the teams. You'll this for the teams. You'll this for the teams. You'll need real-world need real-world need real-world examples: "Hey, this is examples: "Hey, this is examples: "Hey, this is why I need this why I need this ." Here is the workflow ." Here is the workflow ." Here is the workflow I want to I want to I want to implement." implement." implement." The trick here is The trick here is The trick here is that if you don't that if you don't that if you don't get those permissions, get those permissions, get those permissions, if you work in a if you work in a if you work in a company now where company now where company now where you're not allowed to you're not allowed to you're not allowed to use use use agents, most agents, most agents, most people people people will use will use will use their personal cloud their personal cloud their personal cloud subscriptions, their subscriptions, their subscriptions, their personal personal personal ChatGPT subscriptions, installing them ChatGPT subscriptions, installing them ChatGPT subscriptions, installing them on their laptops, because they on their laptops, because they on their laptops, because they get a tangible get a tangible get a tangible benefit from benefit from benefit from using AI. using AI. using AI. The company simply does not The company simply does not The company simply does not provide provide provide official permission for this. official permission for this. official permission for this. They will still They will still They will still do their job. do their job. do their job. We call this We call this We call this shadow AI. Just like shadow AI. Just like shadow AI. Just like shadow IT, when shadow IT, when shadow IT, when you bring your own you bring your own you bring your own virtual machines, virtual machines, virtual machines, your own technology into the your own technology into the your own technology into the company to company to company to get the job done.

  10. get the job done. get the job done. Shadow AI is Shadow AI is Shadow AI is simply the simply the simply the unauthorized unauthorized unauthorized use of AI on use of AI on use of AI on your laptops. This is a your laptops. This is a your laptops. This is a real problem real problem real problem because when because when because when AI gets AI gets AI gets onto your laptop through a onto your laptop through a onto your laptop through a personal subscription, personal subscription, personal subscription, the company doesn't know what's the company doesn't know what's the company doesn't know what's going on, and going on, and going on, and agent-based AI agent-based AI agent-based AI can usually do a lot of can usually do a lot of can usually do a lot of damage very quickly. We're damage very quickly. We're damage very quickly. We're starting to see a starting to see a starting to see a new term in the industry new term in the industry — "ninja AI," which is — "ninja AI," which is — "ninja AI," which is covert AI at covert AI at covert AI at scale, where it's not just one scale, where it's not just one scale, where it's not just one agent breaking something, but agent breaking something, but agent breaking something, but lots of agents lots of agents lots of agents doing lots of things doing lots of things doing lots of things in an organization that in an organization that in an organization that no one knows about no one knows about no one knows about until it's too late until it's too late until it's too late and everything breaks. and everything breaks. So, if you're So, if you're going to going to going to implement AI in implement AI in implement AI in your company, you your company, you your company, you have to make sure the have to make sure the have to make sure the results are results are results are positive, positive, positive, right? Typically, right? Typically, right? Typically, companies approach companies approach companies approach us and start with us and start with us and start with developers developers developers because they because they because they benefit the most benefit the most benefit the most from AI, but you from AI, but you from AI, but you have to be have to be have to be flexible. You flexible. You flexible. You need to need to need to rethink your rethink your rethink your architecture. You architecture. You architecture. You need to need to need to rethink how you rethink how you rethink how you will protect your will protect your will protect your organization from organization from organization from incidents such as incidents such as incidents such as the deletion of the deletion of the deletion of database agents, database agents, database agents, personal data, the personal data, the personal data, the uploading of uploading of customer information, or, in fact, the customer information, or, in fact, the leakage of leakage of company intellectual property onto the company intellectual property onto the public internet.

  11. public internet. So, once you So, once you decide decide decide to implement AI, you will to implement AI, you will to implement AI, you will definitely need to definitely need to definitely need to talk talk talk to security experts to security experts . What are they worried about? . What are they worried about? . What are they worried about? What worries the Chief What worries the Chief What worries the Chief Information Information Information Security Officer (CISO)? How do I Security Officer (CISO)? How do I Security Officer (CISO)? How do I stop agents from stop agents from stop agents from violating best violating best violating best practices? How do I practices? How do I practices? How do I set boundaries for set boundaries for set boundaries for these agents, right these agents, right ? I personally ? I personally ? I personally talk to CISOs talk to CISOs talk to CISOs about once or about once or about once or twice a week and twice a week and twice a week and they say, “Hey, we they say, “Hey, we they say, “Hey, we understand the value of understand the value of understand the value of AI. We want AI. We want AI. We want to implement AI. We to implement AI. We to implement AI. We want people to want people to want people to move as move as move as fast as possible on the fast as possible on the AI ​​superhighway, but I AI ​​superhighway, but I need safety nets need safety nets need safety nets for them, right? And I can't for them, right? And I can't for them, right? And I can't just have just have just have my my my platform team or my platform team or my platform team or my business team business team business team come to me and come to me and come to me and say, "Hey, we say, "Hey, we say, "Hey, we need AI. I need AI. I need AI. I need you to need you to need you to approve this because if approve this because if approve this because if something goes wrong, it's something goes wrong, it's something goes wrong, it's only the only the only the security team's fault, not security team's fault, not security team's fault, not anyone else's, right?" And anyone else's, right?" And anyone else's, right?" And they don't want to be they don't want to be they don't want to be pointed at pointed at pointed at because because because someone used someone used someone used agent-based AI without agent-based AI without agent-based AI without knowing what they were doing, or knowing what they were doing, or knowing what they were doing, or because they didn't have the because they didn't have the because they didn't have the proper proper proper safeguards in place for safeguards in place for safeguards in place for using agents using agents using agents in the company.

  12. in the company. Platform administrators, DevOps, Platform administrators, DevOps, infrastructure infrastructure infrastructure engineers, and engineers, and engineers, and security professionals are concerned about security professionals are concerned about security professionals are concerned about observability. observability. observability. What do these agents do? What do these agents do? What do these agents do? How do I find out what How do I find out what How do I find out what they are doing? How do I they are doing? How do I they are doing? How do I display each of display each of display each of their requests to the their requests to the their requests to the LLM provider in LLM provider in LLM provider in some some some monitoring tool? And how monitoring tool? And how monitoring tool? And how can I set up can I set up can I set up notifications for this notifications for this notifications for this without overloading the without overloading the without overloading the system and getting system and getting system and getting tired of them? tired of them? tired of them? So, another thing that's So, another thing that's So, another thing that's happening is that happening is that happening is that we may we may we may get some get some get some observability for observability for observability for AI, but now the AI, but now the AI, but now the notifications are pouring in notifications are pouring in notifications are pouring in from all directions. When from all directions. When notification fatigue sets in, you notification fatigue sets in, you stop paying stop paying stop paying attention to what's attention to what's attention to what's actually actually actually happening. Everything happening. Everything happening. Everything AI does AI does AI does becomes becomes becomes noise, and you miss the noise, and you miss the noise, and you miss the truly critical truly critical truly critical things that need things that need things that need attention. And one more thing: how do attention. And one more thing: how do attention. And one more thing: how do I implement AI in a I implement AI in a I implement AI in a way that is way that is way that is repeatable, repeatable, repeatable, consistent, reliable, consistent, reliable, consistent, reliable, and safe for everyone and safe for everyone and safe for everyone in the company? Ultimately, in the company? Ultimately, in the company? Ultimately, developers will also developers will also developers will also have have have concerns. There's a concerns. There's a concerns. There's a real "holy real "holy real "holy war" going on, where some of the war" going on, where some of the war" going on, where some of the most experienced most experienced most experienced technical experts technical experts technical experts still don't believe that AI still don't believe that AI still don't believe that AI can write code better can write code better can write code better than them, right? They than them, right? They than them, right? They worry about worry about worry about technical debt, technical debt, technical debt, bloated code, bloated code, security vulnerabilities, and the fact that they security vulnerabilities, and the fact that they will spend time will spend time will spend time fixing fixing fixing AI bugs instead of AI bugs instead of AI bugs instead of doing everything themselves. And doing everything themselves. And doing everything themselves. And if they turn if they turn if they turn Claude on full Claude on full Claude on full power and have power and have power and have him generate a bunch of him generate a bunch of him generate a bunch of merge requests (PRs), merge requests (PRs), merge requests (PRs), how do I make sure how do I make sure how do I make sure this agent doesn't this agent doesn't this agent doesn't do anything that do anything that do anything that will cause me will cause me will cause me problems? After all, in the end

  13. problems? After all, in the end , someone will be held , someone will be held , someone will be held responsible responsible responsible if an agent does if an agent does if an agent does something we something we something we didn't expect from him. didn't expect from him. So I'll tell you how you So I'll tell you how you can implement can implement can implement all these all these all these protection mechanisms that everyone is protection mechanisms that everyone is protection mechanisms that everyone is worried about. First, worried about. First, worried about. First, these are cloud these are cloud these are cloud development environments, and that's exactly what development environments, and that's exactly what Coder does, Coder does, Coder does, right? You need a right? You need a right? You need a remote remote remote execution level. You execution level. You execution level. You need a remote need a remote need a remote environment. You don't environment. You don't environment. You don't want this on want this on want this on your laptop. You your laptop. You your laptop. You want to follow the want to follow the want to follow the link. You want to link. You want to link. You want to use RDP. use RDP. You want You want to connect via SSH to connect via SSH to connect via SSH not to your own not to your own not to your own laptop, but to something laptop, but to something laptop, but to something in a secure in a secure in a secure environment environment environment approved by the approved by the approved by the security team and the security team and the security team and the platform, and platform, and platform, and allow agents allow agents allow agents to write and execute to write and execute to write and execute code in a cloud code in a cloud code in a cloud infrastructure that is infrastructure that is infrastructure that is isolated, has isolated, has isolated, has limited limited limited access rights, and cannot access rights, and cannot access rights, and cannot connect to anything connect to anything connect to anything until you yourself until you yourself until you yourself allow access to the allow access to the allow access to the public internet public internet . This is what it looks like, . This is what it looks like, . This is what it looks like, right? Instead of right? Instead of right? Instead of storing everything on a storing everything on a storing everything on a local device, local device, local device, you're using an you're using an you're using an isolated cloud isolated cloud isolated cloud environment, right?

  14. environment, right? environment, right? Now you can Now you can Now you can only work with the only work with the only work with the code that is there. He code that is there. He code that is there. He only has access to only has access to only has access to the credentials the credentials the credentials that are there. that are there. that are there. It only has access It only has access It only has access to the data that you have to the data that you have to the data that you have deliberately added to this deliberately added to this deliberately added to this development environment. development environment. development environment. Of course? CDEs Of course? CDEs Of course? CDEs speed up speed up speed up AI performance because AI performance because AI performance because if you take a project if you take a project if you take a project and load it and load it and load it onto your laptop, what do you onto your laptop, what do you onto your laptop, what do you need to do to need to do to need to do to run it? You run it? You run it? You need to download the need to download the need to download the dependencies. You dependencies. You dependencies. You need to update need to update need to update your paths. If you have your paths. If you have Python Python version 3 installed on your computer and your version 3 installed on your computer and your version 3 installed on your computer and your project requires the project requires the project requires the second version, second version, second version, conflicts will arise. conflicts will arise. conflicts will arise. You will have to You will have to You will have to create create create virtual virtual virtual environments. There's environments. There's environments. There's a lot of a lot of a lot of extra work to do, which extra work to do, which extra work to do, which while won't break your while won't break your while won't break your laptop, you laptop, you laptop, you probably won't want probably won't want probably won't want to waste time on. to waste time on. to waste time on. It would be better to have a It would be better to have a It would be better to have a stable cloud stable cloud stable cloud environment already environment already environment already set up for set up for set up for this application to run, this application to run, this application to run, right? So everything right? So everything right? So everything Coder does to Coder does to Coder does to help developers is help developers is free them from free them from free them from having to having to having to dig around in a terminal dig around in a terminal dig around in a terminal or configure or configure or configure their own laptop. They their own laptop. They their own laptop. They can simply can simply can simply jump into this jump into this jump into this lightweight or powerful lightweight or powerful lightweight or powerful virtual machine, virtual machine, virtual machine, where everything is ready, and where everything is ready, and where everything is ready, and start developing right away start developing right away start developing right away . The same . The same . The same goes for agents, goes for agents, goes for agents, right? If you right? If you right? If you deploy an agent on a deploy an agent on a deploy an agent on a clean system and clean system and clean system and say, "Download say, "Download say, "Download this repository from GitHub this repository from GitHub this repository from GitHub and run the project." What and run the project." What and run the project." What will he do? He will he do? He will he do? He will read the contents. He'll will read the contents. He'll will read the contents. He'll say, "Oh, I say, "Oh, I say, "Oh, I need to start need to start need to start uploading files uploading files ." You never know ." You never know ." You never know where he'll where he'll where he'll download these download these download these things from. And if he takes things from. And if he takes things from. And if he takes them from some registry, them from some registry, them from some registry, that registry could be

  15. that registry could be that registry could be compromised. You compromised. You compromised. You want everything want everything want everything ready in advance ready in advance ready in advance so the agent can so the agent can so the agent can get started right away. get started right away. Next is the proxy server for models. server for models. It is simply an intermediary It is simply an intermediary between the agent or between the agent or between the agent or model on your model on your model on your device and the device and the device and the LLM provider; LLM provider; LLM provider; traffic must pass traffic must pass traffic must pass through a node where we through a node where we through a node where we can track can track can track and log every and log every and log every action. Here you see action. Here you see that in a typical that in a typical that in a typical scenario, the agent scenario, the agent scenario, the agent is located somewhere and is located somewhere and is located somewhere and can go can go can go directly to the internet, directly to the internet, directly to the internet, directly to the directly to the directly to the model provider, model provider, model provider, to get what it to get what it to get what it needs. But needs. But needs. But the solution is actually the solution is actually the solution is actually simple, isn't it? simple, isn't it? simple, isn't it? Before the agent Before the agent Before the agent contacts the contacts the contacts the model provider, model provider, model provider, it hits your it hits your it hits your proxy, proxy, proxy, goes through your goes through your goes through your gateway, right? It can gateway, right? It can gateway, right? It can clear data, clear data, clear data, remove injections. remove injections. remove injections. If you accidentally If you accidentally If you accidentally enter your credit enter your credit enter your credit card details in a request, you card details in a request, you card details in a request, you don't want them to don't want them to don't want them to end up with the end up with the end up with the LLM provider. The proxy LLM provider. The proxy server can delete server can delete server can delete this data and record this data and record this data and record everything that happens.

  16. everything that happens. And finally, you And finally, you need a firewall for need a firewall for need a firewall for agents. So when an agents. So when an agents. So when an agent starts agent starts agent starts execution at the execution at the execution at the process level, you want process level, you want process level, you want to be sure that it to be sure that it to be sure that it can't run can't run can't run commands that you haven't commands that you haven't commands that you haven't approved, right? So, in approved, right? So, in approved, right? So, in this remote this remote this remote environment that environment that environment that connects to a connects to a connects to a proxy, if an agent for proxy, if an agent for proxy, if an agent for some reason some reason some reason runs a "GH repo delete" runs a "GH repo delete" runs a "GH repo delete" or deletes a table, or deletes a table, or deletes a table, you'll need you'll need you'll need some kind of agent some kind of agent some kind of agent firewall that firewall that firewall that analyzes the analyzes the analyzes the process logs and blocks process logs and blocks process logs and blocks such actions. This command such actions. This command such actions. This command is rejected. So, is rejected. So, is rejected. So, these are three architectural these are three architectural these are three architectural ways you can ways you can ways you can protect your protect your protect your organization from an organization from an organization from an agent getting out of agent getting out of agent getting out of control. control. control. We don't have time for We don't have time for We don't have time for a demonstration at the moment, but a demonstration at the moment, but a demonstration at the moment, but if you are interested, if you are interested, if you are interested, please come by please come by please come by our Curder booth. We our Curder booth. We our Curder booth. We are opposite are opposite are opposite this stage, slightly to this stage, slightly to this stage, slightly to the left. And a few the left. And a few the left. And a few key takeaways, key takeaways, key takeaways, right? Agents are powerful, right? Agents are powerful, right? Agents are powerful, but beware of but beware of but beware of this dangerous this dangerous this dangerous trio. Make sure trio. Make sure trio. Make sure you have a way you have a way you have a way to see everything to see everything to see everything this agent does. It's this agent does. It's this agent does. It's okay to move okay to move okay to move slowly to think slowly to think slowly to think through your through your through your architecture and architecture and architecture and understand what understand what your infrastructure really needs.

  17. your infrastructure really needs. My name is Michael My name is Michael My name is Michael Patterson, I'm a Patterson, I'm a Patterson, I'm a lead lead lead solutions engineer. I would be happy to solutions engineer. I would be happy to solutions engineer. I would be happy to chat with chat with chat with you about how you can you about how you can you about how you can safely develop safely develop safely develop products products products using agents. using agents. using agents. Thank you for your time.

Summary

The presentation focuses on the challenges of agent-based AI in 2025, highlighting the "deadly trio" of security vulnerabilities, potential for data destruction, and the difficulty of safe development. The speaker uses examples like "vibe coding" and Open Claw to illustrate these risks. The practical takeaway is that Coda is offering solutions to address these agent security principles and enable companies to scale AI responsibly.

View original episode ↗