We let an AI agent execute Bash and lived to talk about it
Sarah Sanders
- When
- Thursday, July 22:25 PM – 2:45 PM · 20 min
- Where
- Main StageSan Francisco, CA · imported from ai.engineer's public schedule feed
About this session
PostHog's Wizard agent can read your codebase, install packages, and run shell commands on your laptop. Yes, on purpose. This talk covers how we went from "defense-in-hope" to a standalone, robust security service. It'll highlight results from a pentest that made us question our life choices, an internal audit that challenged our architecture, and the debate over how to secure the entire pipeline. You'll learn why "scan-then-trust" is a weaker model than you think, what it takes to build kill switches you hope you never use, and what happens when you pentest an AI agent that has access to Bash.
Speaker
More in Harness Engineering
- In Code They Act, In Proof We TrustTuesday, June 30 · 4:50 PM – 5:10 PM · Main Stage
- The 2026 State of AI EngineeringThursday, July 2 · 9:00 AM – 9:20 AM · Main Stage
- The Unreasonable Effectiveness of Separating the Task from the ModelThursday, July 2 · 9:40 AM – 10:00 AM · Main Stage
- How Anthropic Builds: Lessons from LabsThursday, July 2 · 10:00 AM – 10:20 AM · Main Stage
- Tokens Should Have JobsThursday, July 2 · 10:45 AM – 11:05 AM · Main Stage
For developers: this programme is open data — JSON, iCal, schedule XML and an MCP endpoint.Show endpointsHide
- JSONEvery published session and speaker, in one request./aie-worldsfair-2026-import/feed.json
- iCalSubscribe in Google, Apple or Outlook Calendar./aie-worldsfair-2026-import/feed.ics
- Schedule XMLfrab / pentabarf — the format conference apps import./aie-worldsfair-2026-import/feed.xml
- MCP + RESTPoint Claude at the programme. OpenAPI 3.1 included./agents
No key, no signup, CORS open. Everything here is generated from the same data the organisers edit.