When Your AI Becomes the Breach: The Hidden Dangers of Agentic Skills
This episode investigates how the rise of autonomous AI agents creates a critical new attack surface through vulnerable ”skills” and protocols, requiring a shift to zero-trust governance to prevent your assistant from becoming an insider threat
🎧 Listen to this Episode
Show Notes
We explore the rapid paradigm shift from passive chatbots to autonomous "agentic" AI, where new standards like the Model Context Protocol (MCP) grant systems the power to execute code and access sensitive files. Drawing on a massive empirical study of over 31,000 agent skills and real-world espionage campaigns like GTG-1002, we expose how attackers leverage "tool poisoning" and indirect prompt injection to hijack these agents for data exfiltration. Finally, we unpack essential defense strategies, including the NIST AI Risk Management Framework and the new OWASP Top 10 for Agentic Applications, to help organizations close the dangerous "consent gap" between user permissions and agent actions.
- https://cisomarketplace.com/blog/agentic-desktop-agents-ai-local-file-access-security
- https://cisomarketplace.com/blog/agentic-browser-revolution-ciso-guide-ai-attack-surface
- https://cisomarketplace.com/blog/workflow-automation-blind-spot-zapier-n8n-power-automate-security
- https://cisomarketplace.com/blog/ai-agent-security-crisis-mcp-vulnerabilities
- https://cisomarketplace.com/blog/agent-skills-next-ai-attack-surface
- https://breached.company/over-1-000-clawdbot-ai-agents-exposed-on-the-public-internet-a-security-wake-up-call-for-autonomous-ai-infrastructure/
Sponsors:
https://compliance.airiskassess.com
https://cloudassess.vibehack.dev
Share this episode
Enjoying CISO Insights?
Subscribe to get new episodes delivered directly to your podcast app.
Related Episodes
The Identity Horizon: Cybercrime's Machine-Speed Evolution
A deep-dive investigation into how cybercrime has industrialized in 2026 through autonomous AI agents, identity-based compromises, and nation-state-backed extortion...
▶️ Listen Now
Unplugging the AI Grid: Your 2026 Social Media Privacy Survival Guide
This podcast provides a comprehensive, actionable roadmap for opting out of platform AI data harvesting, strengthening account security, and navigating 2026 global privacy regulations...
▶️ Listen Now
Growing Up Digital: Safeguarding Youth in the EU
This podcast investigates how the European Union and its local municipalities are implementing rights-based legal frameworks, multi-agency coordination, and educational strategies to protect minors fr...
▶️ Listen Now