AI Agents Gone Rogue? Build, Defend & Attack AI-Enabled Apps • Katie Paxton-Fear • YOW! 2025

AI Agents Gone Rogue? Build, Defend & Attack AI-Enabled Apps • Katie Paxton-Fear • YOW! 2025

🎙 Katie Paxton-Fear 👥 1.1M 📅 August 18, 2026 ⏱ 31 min 👁 10 📄 expert opinion 🧭 2026-08-18
Available in: English (current) Français

Keywords

AI agentssecurityprompt injectionMCPvibe coding

Summary

Katie Paxton-Fear, a security advocate and former bug bounty hunter, presents a talk on the security implications of AI agents. She begins by defining AI agents and explaining how they work, emphasizing that they are not just LLMs but involve frameworks, tools, and integrations. She then outlines six key areas of concern: socially engineering agents, hacking agentic frameworks, malicious agents in the loop, AI as accidental insider, hackbots, and the future. She provides real-world examples, such as the NPM package compromise that attempted to use Claude, and the Replit database deletion incident. She discusses the risks of prompt injection, the vulnerabilities in underlying infrastructure like MCP, and the potential for AI to be used in offensive operations. She concludes by highlighting the need for traditional security measures and awareness of the expanding attack surface.

134 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into the emerging security challenges of AI agents, supported by concrete examples and personal experiences. The argumentation is solid, as the speaker systematically addresses each threat category with evidence and practical implications. She effectively argues that AI agents introduce new attack vectors while also reminding that traditional vulnerabilities persist. The talk is persuasive and well-structured, making a strong case for proactive security measures.

Scientific Rigor, Source Quality, Title Accuracy

The speaker demonstrates scientific rigor by referencing real incidents and providing links to resources in the description. However, the talk lacks formal citations and relies on anecdotal evidence and personal experience. The title accurately reflects the content, and the talk is well-organized. The speaker’s credibility as a security researcher adds to the reliability of the information.

139 words

Title / Content Match

The title accurately reflects the content, which covers building, defending, and attacking AI-enabled applications.

Quality & Reliability

8/10

The talk is given by a recognized security researcher with a PhD in AI and cybersecurity, and includes real-world examples and references to actual incidents. However, it is a conference talk with limited depth and no formal citations, so the score is high but not perfect.

Chapters

Cited Sources

Concurring Sources

  • OWASP Top 10 for LLM Applications — Provides a list of common vulnerabilities in LLM applications, aligning with the talk's themes.
  • Anthropic's Responsible Scaling Policy — Discusses safety measures for AI, relevant to the talk's discussion of AI security.

Dissenting Sources

  • AI agents are not a security threat — Some argue that AI agents are not fundamentally different from other software and that existing security measures suffice. This talk challenges that by highlighting novel attack vectors.

External References

Contribution & Novelties

The talk provides a comprehensive overview of AI agent security threats, synthesizing current knowledge and real-world examples. It highlights the often-overlooked attack surface of agent frameworks and the potential for AI to be used in offensive operations. The speaker’s perspective as a security researcher adds credibility.

Pour aller plus loin :

86 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a talk that is informative and credible but not overly technical. The overall balance suggests a well-rounded presentation suitable for a broad technical audience.

Reliability 8/10

💬 No comments were provided for analysis.