18 augusti 2026
35 min
In a world where agents are chaining vulnerabilities together to escape sandboxes, simply blocking bad packages is not enough. Ahmad Nassri, CTO of Socket and previously CTO of npm, joins us live at Black Hat to explain what happens when you deny a coding agent a package: it becomes a risk if the agent thinks it can help it complete its goal later.
Socket has watched agents blocked from an install go straight to the CDN to pull the tarball directly, or rewrite the registry configuration in the local environment and resolve npm by DNS to fetch it another way. For this reason Socket's answer is not a simple denial. Because the enforcement point sits at the network level, Socket changes what the agent and the package manager see in the first place, masking the bad versions so that, as Ahmad puts it, as far as the agent is concerned those versions do not exist.
We talk through the Hugging Face incident where an OpenAI agent found a zero-day in a package registry proxy, how Socket detects a malicious package within minutes of publication, and why agent security is layered: safe packages, short-lived and task-scoped credentials, and real-time visibility into what the agent actually did.
Lyssna på fler avsnitt från
Insecure Agents
Visar 1–10 av 54 avsnitt
27 augusti 2026
32 min
25 augusti 2026
41 min
20 augusti 2026
49 min
14 augusti 2026
34 min
12 augusti 2026
29 min
5 augusti 2026
51 min
28 juli 2026
27 min
23 juli 2026
28 min
21 juli 2026
27 min
17 juli 2026
28 min