We let an AI agent execute Bash and lived to talk about it — Sarah Sanders, PostHog
AI Engineer
Building agentic CLI tools requires a shift from simple prompt-based security to deterministic, layered defense. The PostHog Wizard, an agent that automates software setup, demonstrates that tools with command execution capabilities function as "malware starter packs" if left unchecked. Security must be enforced deterministically; relying on LLMs for enforcement is unreliable. Implementing a tool like the Warlock—which uses YARA for pattern matching—allows for mechanical, predictable blocking of malicious inputs or behaviors. Furthermore, security risks extend beyond user input to the supply chain itself, where poisoned documentation or prompts can compromise the agent. Because attacks often emerge from the interaction of multiple seemingly benign features, developers must scan content at both the source and the point of use, ensuring that detection and enforcement remain strictly separated from probabilistic judgment.
Sign in to continue reading, translating and more.
Open full episode in Podwise
