The Hidden Security Risks of AI Coding Agents

The Hidden Security Risks of AI Coding Agents

Author: Tessl May 19, 2026 Duration: 41:45
Your AI coding agent has access to your secrets, pulls in content from the outside world, and can run shell commands. According to Joe Holdcroft, that combination makes you one prompt injection away from a very bad time. The tools haven't changed the fundamentals of security — they've just made every existing risk move faster, and introduced a few genuinely new ones. What we cover: Why the "lethal trifecta" of agent capabilities creates a novel threat surfaceHow text and markdown files have b...

Hosted by Guy Podjarny and Simon Maple, The AI Native Dev-from Copilot today to AI Native Software Development tomorrow is a conversation about the profound shift happening right now in how software is created. This isn't just another tech show about using the latest AI tool; it's a deep, ongoing exploration of what it means to build software in an age where artificial intelligence is a fundamental partner. Each episode unpacks the practical realities and the long-term implications of this transition, moving beyond today's assistive copilots to imagine the workflows, team structures, and architectural decisions of a fully AI-native future. For developers and engineering leaders who feel both the excitement and the uncertainty of this moment, the podcast offers grounded discussions, expert insights, and forward-thinking analysis. You'll hear concrete examples of AI's current impact on coding practices alongside speculative, thoughtful debates about where this all might lead. The dialogue is shaped by a genuine curiosity about how we can actively guide this transformation rather than just react to it. Tune in for a nuanced perspective that treats AI not as a simple productivity hack, but as the core of a new development paradigm that is still being written. This Tessl production provides a essential space for anyone invested in the craft of building software to understand and help shape what comes next.
Author: Language: en-us Episodes: 100

The AI Native Dev - from Copilot today to AI Native Software Development tomorrow
Podcast Episodes
We Scanned 3,984 Skills — 1 in 7 Can Hack Your Machine [not-audio_url] [/not-audio_url]

Duration: 35:17
Most developers install skills without reading what's inside them. But that's exactly what attackers are counting on. Simon Maple sits down with Brian Vermeer from Snyk at DevNexus to get into the security risk hiding in…
The Greatest Time to Build a Startup (The AI-Native Advantage) [not-audio_url] [/not-audio_url]

Duration: 1:01:57
The best agentic developers throw away their agent's work without guilt, run three agents at once and only use one, and treat their AI like a junior developer they genuinely dislike. It sounds wrong. It works. Daniel Jon…
Why Your Agent Needs Memory, Not Just Context [not-audio_url] [/not-audio_url]

Duration: 44:24
Not onboarding your agent is on you. Richmond Alake, Director of AI Developer Experience at Oracle, joins Simon Maple to make the case that most agent failures come down to one thing: memory. Not the model, not the infra…
Cisco Principal Engineer's Fix for AI Code Security [not-audio_url] [/not-audio_url]

Duration: 34:03
Your AI coding agent learned from millions of lines of code, including insecure ones. That means by default, it can write vulnerable code too. So how do you fix that? John Groetzinger, Principal Engineer at Cisco, built…
Why Context Beats Every Prompt You'll Ever Write [not-audio_url] [/not-audio_url]

Duration: 31:09
Most teams think agentic dev is about writing better prompts. It's not. Guy Podjarny and Simon Maple explain why managing context, not crafting prompts, is what separates teams that scale with agents from teams that don'…
From IBM Acquisition to AI-Native Observability | Dash0 CEO [not-audio_url] [/not-audio_url]

Duration: 56:31
"Charts are good for users, not good for agents. Agents look at the underlying data and do deep analysis." Mirko Novakovic built Instana, sold it to IBM, and now he's building Dash0, rethinking observability for agents,…
The End of Fragmented Agent Context [not-audio_url] [/not-audio_url]

Duration: 44:49
One skill took coding success from 28% to 71%. Another made things worse. Guy Podjarny and Simon Maple tested 1000+ agent skills and reveal which ones actually work, which hurt performance, and why anecdotal evidence isn…
The Developer Skills That Will Actually Survive AI [not-audio_url] [/not-audio_url]

Duration: 56:39
“You have to prioritize between the thing you want to do and the thing that actually is driving the business, that’s what really big companies are fighting every single day.” As former CEO of GitHub and now a startup fou…
How Too Much Information Destroys Agent Performance [not-audio_url] [/not-audio_url]

Duration: 20:53
Most AI agents fail because you're using them wrong. Here’s what actually works in production. In this episode, Simon Maple sits down with Itamar Friedman (CEO of Qodo) and Robert Brennan (CEO of OpenHands) at QCon AI. T…
Intelligence ≠ Knowledge: Why Context Beats Bigger Models [not-audio_url] [/not-audio_url]

Duration: 1:12:28
In this special milestone episode, Simon Maple and Guy Podjarny celebrate 1 million views by looking back at the chaos of 2025 and forecasting the high-stakes reality of 2026. On the docket: • Why appearing on this show…