We Gave an Agent Production Code Access and Then Tried to Sleep at Night
Moritz Johner
- When
- Tuesday, June 3011:40 AM – 12:00 PM · 20 min
- Where
- Track 5San Francisco, CA · imported from ai.engineer's public schedule feed
About this session
We let an agent touch production code to fix CVEs. That is either automation or a supply chain incident, depending on how honest your architecture is. PatchPilot started simple: find vulnerable dependencies, patch them, open a PR, let CI prove the fix, move on. Then reality showed up. The agent needed repository access, CI logs, credentials, and a Docker socket. Without that, it was useless. With it, every security reviewer in the room had a point. This is the production case study: what we gave the agent, what we refused, what infosec pushed back on, and where they were right. We will cover scoped permissions, constrained PRs, audit trails, approval gates, CI evidence, credential boundaries, and the gap between "it generated a patch" and "we can defend this change." Agentic remediation is not just developer productivity. It is a new participant in your software supply chain.
Speaker
Staff Engineer, Form3
Staff Engineer at Form3, focused on Kubernetes, security, and platform engineering. One of the creators and maintainers of external-secrets.
More in Security
- Through the AI Fog: The architectural decision the next 24 months of agentic security depends on.Tuesday, June 30 · 10:45 AM – 11:05 AM · Track 5
- Your LLM Stack Is a 2008 Database With Better Marketing: Why ML Security Is Dominated by Misconfiguration, Not Missing FeaturesTuesday, June 30 · 11:10 AM – 11:30 AM · Track 5
- Agentic Development SecurityTuesday, June 30 · 12:05 PM – 12:25 PM · Track 5
- Using LLMs to Secure Source CodeTuesday, June 30 · 1:30 PM – 1:50 PM · Track 5
- Dual-Surface Architecture: Serving Humans and Agents from the Same Tool LayerTuesday, June 30 · 1:55 PM – 2:15 PM · Track 5
For developers: this programme is open data — JSON, iCal, schedule XML and an MCP endpoint.Show endpointsHide
- JSONEvery published session and speaker, in one request./aie-worldsfair-2026-import/feed.json
- iCalSubscribe in Google, Apple or Outlook Calendar./aie-worldsfair-2026-import/feed.ics
- Schedule XMLfrab / pentabarf — the format conference apps import./aie-worldsfair-2026-import/feed.xml
- MCP + RESTPoint Claude at the programme. OpenAPI 3.1 included./agents
No key, no signup, CORS open. Everything here is generated from the same data the organisers edit.