Ep. 72 - The File That Lies: One CLAUDE.md Walks Off With Your Agent's Credentials
A poisoned CLAUDE.md file inside a cloned repository quietly tells a coding agent to send its test logs to an outside endpoint, and the agent complies, shipping environment details, internal system information, and API keys to a server the developer never controlled. The model was not broken. It was obedient. In this episode of The Cyber Resilience Brief (a SafeBreach podcast), host Tova Dvorin and SafeBreach senior sales engineer Adrian Culley break down why building agentic AI controls is not the same as proving they hold under attack.
They cover why the agentic attack surface is fluid rather than static, why loaded state like config files, MCP tool descriptors, and vector stores are durable attack vectors, and what adversarial validation actually looks like for each of the five core agent guardrails: sandboxing, permissions, pre-tool hooks, prompt injection defense, and pre-commit gates. Along the way: Model Context Protocol (MCP) security, context window poisoning, Unicode hook bypass, cross-agent prompt injection, breach and attack simulation (BAS), and SafeBreach's Adversarial Exposure Validation (AEV) platform.
TIMESTAMPS & CHAPTERS
00:00 What do this week's agentic AI posts get right?
00:43 Where do the developer guides stop short?
01:37 What does an untested agent deployment look like?
02:01 Why is the agentic attack surface fluid?
02:46 What makes config files durable attack vectors?
03:29 How does a CLAUDE.md file leak credentials?
04:13 Is autonomous agent risk real or theoretical?
04:53 What does validating controls actually mean?
06:01 How do you test the five agent guardrails?
08:23 Do your pre-commit gates actually trip?
09:28 Where should a CISO start on Monday?
12:07 How is this different from pen testing?
13:51 What agent security gap comes next?
RESOURCES & LINKS MENTIONED
Learn about SafeBreach Adversarial Exposure Validation (AEV): https://www.safebreach.com/safebreach-exposure-validation-platform/
Read the blog post: What the OpenAI-Hugging Face Incident Reveals for Every Security Program
https://www.safebreach.com/blog/openai-hugging-face-ai-breach-security-testing/
Follow The Cyber Resilience Brief on LinkedIn: https://www.linkedin.com/showcase/108491646/admin/dashboard/
ABOUT THE CYBER RESILIENCE BRIEF
The Cyber Resilience Brief is a cybersecurity podcast dedicated to analyzing real-world threats, data breaches, and offensive security strategies. Hosted by Tova Dvorin and featuring expert commentary from Adrian Culley, we bring board-level risk conversations down to actionable technical insights.
#Cybersecurity #AISecurity #AgenticAI #MCP #PromptInjection #InfoSec #CISO #BAS #AEV
Spotify: https://open.spotify.com/episode/5UhqdDTIFkptBDHhWYJyMi
Apple Podcasts: https://podcasts.apple.com/us/podcast/ep-72-the-file-that-lies-one-claude-md-walks-off-with/id1824470698