Skip to content

Details

The Bay Area AI Security Research Meetup picks up where we left off on OWASP LLM03:2026 Excessive Agency. Last session covered the foundations: what agents, tools and harnesses actually are, and how excessive functionality, permissions and autonomy turn into real attacks. This Sunday we go hands-on: hardening Claude Code against each LLM03 criterion : permission modes, settings scopes (user project / local managed), sandboxing, hooks, and how to see transparently what an agent can already touch before you trust it with anything. We'll map every control back to the chapter's mitigations and pressure-test what holds up.

We'll also have a talk and live demo from Andy Chan (embedded systems and platform security consultant) on instruction-file injection in AI coding agents. He'll reconstruct a real incident : a fake take-home interview repo where a poisoned .cursor/rules file plus a repo-supplied MCP tool got an agent to hand over AWS and kube credentials in under two minutes, from one innocent "how do I run this?", then cover which models refuse, why the model isn't the control, and the deterministic defenses that actually stop it.

To attend or present, email aisecurityinbay@proton.me.

Related topics

You may also like