YouTube14 Sept 2026
21m

We let an AI agent execute Bash and lived to talk about it — Sarah Sanders, PostHog

Podcast cover

AI Engineer

Building agentic CLI tools requires a shift from simple prompt-based security to deterministic, layered defense. The PostHog Wizard, an agent that automates software setup, demonstrates that tools with command execution capabilities function as "malware starter packs" if left unchecked. Security must be enforced deterministically; relying on LLMs for enforcement is unreliable. Implementing a tool like the Warlock—which uses YARA for pattern matching—allows for mechanical, predictable blocking of malicious inputs or behaviors. Furthermore, security risks extend beyond user input to the supply chain itself, where poisoned documentation or prompts can compromise the agent. Because attacks often emerge from the interaction of multiple seemingly benign features, developers must scan content at both the source and the point of use, ensuring that detection and enforcement remain strictly separated from probabilistic judgment.

Outlines

Sign in to continue reading, translating and more.

Open full episode in Podwise