Skip to main content
bash TV

AI Security Engineer Foundations + Certificate — Javier Garza, Snyk

AI Engineer

66 views11 Oct 2026

YouTube

An AI bill of materials turns a repository into a searchable inventory of models, datasets and agents. Javier Garza demonstrates the workflow from a CLI scan to a visual dashboard, then asks it which models the project uses. That inventory anchors a broader security problem: teams cannot assess the AI components they do not know are there. The workshop connects shadow AI to prompt injection, supply chain risk, sensitive information disclosure and excessive agency, using Gandalf challenges and malicious instructions embedded in external content to show how an application's intended rules can be bypassed. Garza works through defenses at several layers. A database view can restrict what an assistant is allowed to retrieve; limited permissions, output validation and human approval constrain what it can do next. Threat modeling maps assets, trust boundaries and possible attacks before deployment, with an intentionally vulnerable student assistant offered for practice. For skills and MCP servers, he separates scanning tool definitions for hidden instructions from scanning the underlying code for vulnerabilities, then explains a scan, fix and rescan loop driven by coding agent rules and hooks. The final sections examine secure prompting, dependency verification, separate development and production environments, IDE configuration and developer review. Governance depends on explaining guardrails as well as enforcing them, because unexplained restrictions invite workarounds. He closes with offensive agent workflows, training resources and challenges that let participants test these ideas themselves. Speaker info: - https://www.linkedin.com/in/jjgarza - https://twitter.com/jjaviergarza - https://snyk.io/lp/ai-sec-eng-foundations/ - https://github.com/snyk-workshops/vulnerable-student-assistant Timestamps: 0:00 - Workshop overview 2:16 - Meet Javier Garza 5:30 - OWASP risks for LLM applications 6:42 - Prompt injection and Gandalf 9:01 - Indirect injection through external content 12:02 - Sensitive information disclosure 15:32 - Restrict database access 18:18 - Supply chain risks 23:14 - Poisoning and AI component inventories 24:11 - Output handling and excessive agency 27:26 - Prompt leakage and vector weaknesses 29:04 - Resource consumption and training modules 31:07 - Shadow AI and unsanctioned tools 36:06 - AI bills of materials 38:32 - Inventory a repository from the CLI 41:30 - Explore the inventory dashboard 44:57 - Threat modeling foundations 49:35 - Probabilistic systems and new boundaries 53:03 - MITRE ATLAS and AI threat mapping 56:16 - Discover assets and prioritize threats 59:12 - Vulnerable student assistant practice app 1:00:11 - Bring threat modeling into development 1:04:17 - Securing agent skills and MCP servers 1:09:12 - Tool poisoning and hidden instructions 1:11:24 - Agent scans and code scans 1:14:59 - Command injection and input validation 1:16:24 - Scan, fix, and rescan with rules and hooks 1:21:10 - Secure vibe coding 1:30:19 - Prompting and technology choices 1:40:32 - Secure prompts and environment boundaries 1:43:19 - Hallucinated dependencies and supply chains 1:47:39 - Harden IDE and CLI configuration 1:49:02 - Developer review and security culture 1:51:15 - Organization policies and governance 1:53:22 - Offensive agent workflows 1:55:38 - Training, certificates, and challenges

Join the discussion

Sign in to join the discussion

Sign in