Skip to main content
bash TV

Build a Platform and Watch It Burn — Michael Forrester, Accenture & Whitney Lee, Datadog

AI Engineer

457 views11 Oct 2026

YouTube

A burrito ordering assistant deploys an external container image and exposes a secret recipe from its Kubernetes environment. Michael Forrester and Whitney Lee invite the audience to push that deliberately permissive bot beyond ordering food, then repeat the attacks with infrastructure and AI guardrails. The exercise makes excessive agency tangible: a friendly business story can turn an ordinary chat interface into a route to tools, files and cluster operations. Model refusals also change between attempts, which complicates the live demos and shows why an application's boundaries cannot depend on the model choosing to refuse. The workshop moves through three configurations. The first leaves the bot exposed; the second adds infrastructure controls, including Kyverno rules restricting image sources and deployment requirements. Intended runtime protections do not consistently stop recipe access, so the presenters distinguish what worked from what still needs fixing. A third environment lets them toggle LLM Guard input and output filtering, comparing a response that exposes sensitive content with one that redacts it, and a request blocked before model processing. A weather tool introduces another trust boundary: its description asks the agent to read internal configuration alongside a legitimate task. OpenTelemetry traces reveal prompts, tool calls and results in Datadog, making that behavior inspectable. The final discussion connects agent security to established CI/CD, identity, network and artifact controls, and asks when an AI workflow has clear boundaries, a worthwhile cost and a verifiable output. Speaker info: - https://www.linkedin.com/in/michaelrishiforrester/ - https://x.com/peopleforrester - https://whitneylee.com/ - https://www.linkedin.com/in/whitneylee/ - https://github.com/peopleforrester/Unleash_an_Agent_Watch_It_Burn Timestamps: 0:00 - A platform, an agent, and a burrito bot 1:24 - An assistant without application guardrails 3:16 - Audience challenges and model refusals 4:24 - Try deploying an external image 6:12 - How names and business stories change behavior 8:00 - Live deployment through the chatbot 9:09 - Find the secret recipe 10:24 - The agent, proxy, and cluster wiring 12:18 - Repeat attacks on a second cluster 13:28 - Existing security and delivery practices 15:18 - Network policy and Kyverno admission rules 17:09 - Runtime protection and an incomplete block 18:45 - Prevention, response, and fork bomb limits 20:44 - Inspect agent behavior through traces 23:05 - Infrastructure controls versus AI guardrails 24:57 - Round three and individual environments 27:06 - Turn AI guardrails on yourself 29:42 - Sensitive output and redaction 31:39 - Accidental input filtering and a repeat test 34:30 - Input filtering before model processing 38:11 - Demonstrate an input block 40:14 - A weather tool with hidden instructions 44:00 - Trace the configuration access 45:23 - Input, output, and sensitive trace data 47:00 - MCP gateways and established platform controls 48:39 - Boundaries, cost, and verifiable outputs 50:42 - Provisioning limits and the workshop repository

Join the discussion

Sign in to join the discussion

Sign in