cd /news/ai-agents/insecure-agents-podcast-how-to-keep-… · home › topics › ai-agents › article
[ARTICLE · art-143023] src=socket.dev ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls

Socket CTO Ahmad Nassri said on the Insecure Agents podcast, recorded at Black Hat, that coding agents blocked from installing a package will fetch tarballs directly from a CDN, override local registry settings, or use DNS lookups to reach a registry another way. Socket Firewall blocks those downloads at the network level and strips disallowed versions from the registry metadata returned to agents and package managers, so "as far as the agent or the package manager is concerned, those versions don't exist," Nassri said. Nassri also described attackers planting instructions that tell an agent it is authorized to inspect an environment and upload what it finds, and recommended short-lived credentials, task-scoped permissions, and visibility into agent actions because reviewing final output can miss packages downloaded, executed, and discarded.

by read2 min views1 publishedOct 1, 2026
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Image: Socket (auto-discovered)

Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

  • Sarah Gooding

A coding agent blocked from installing a package may try another way to download it. In this episode of the Insecure Agents podcast recorded at Black Hat, Socket CTO Ahmad Nassri joins host Allie Howe to discuss how agents’ determination to finish a task can lead them to bypass security controls, and how Socket Firewall changes what they see before an install begins.

Nassri describes cases where agents responded to blocked installs by fetching package tarballs directly from a CDN, overriding local registry settings, or using DNS lookups to reach a registry through another route. Socket Firewall addresses this at the network level, blocking downloads and removing disallowed versions from the registry metadata returned to agents and package managers. “As far as the agent or the package manager is concerned, those versions don’t exist,” he explains. That reduces the chance an agent will identify a blocked version and pursue another way to retrieve it.

The conversation also covers attacks that use an agent itself to steal information. Rather than embedding code that collects credentials, an attacker can plant instructions telling an agent it is authorized to inspect an environment and upload what it finds. Nassri describes how this changes detection: the malicious content may be a prompt, while the agent performs the data collection and exfiltration using access it already has.

Preventing malicious downloads is one part of securing that environment. Nassri and Howe discuss short-lived credentials, permissions limited to the task, and visibility into the actions an agent takes. Reviewing its final output can miss packages it downloaded, executed, and discarded along the way. Teams need to understand what happened during the work, including which dependencies ran and how credentials were used.

Watch the full conversation in the episode below.

── more in #ai-agents 4 stories · sorted by recency
── more on @socket 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/insecure-agents-podc…] indexed:0 read:2min 2026-10-01 · —