Uploaded March 2026 | Updated September 2026, 2 weeks ago
Think Model Context Protocol (MCP) is secure by default? No βοΈ Learn the exact framework for selecting and configuring AI agent tools to prevent a 1-line production hijack.
π Giving AI agents "hands and legs" means granting permissions to read files, execute commands, and handle sensitive API keys that can be hijacked by malicious actors. Standard security layers fail to detect supply chain attacks hidden in legitimate tool updates.
In this technical deep-dive, Gil Friedman (Field CTO at Backslash Security) dissects the Model Context Protocol lifecycle and reveals the framework for hardening AI-to-tool connections against unauthorized actions π«
π₯ Gil Friedman is the Field CTO at Backslash Security, specializing in cloud-native AppSec and the security of AI-driven development. With a background leading core engineering teams at Meta and SAP/Concur, he focuses on hardening AI agent workflows and securing the Model Context Protocol (MCP) against sophisticated supply chain attacks in production environments.
π Connect with Gil:
π linkedin.com/in/gilfr
π Learn more about Backslash Security:
π https://www.backslash.security/
π Follow the link to watch the full version of the talk and gain access to all AI Coding Summit recordings:
π gitnation.com/events/ai-coding-summit-2026?utm_source=youtube&utm_medium=GilFriedman
π Timestamps:
00:00 - Giving AI "Hands and Legs": The Power of MCP
00:51 - Why MCP is a Massive Attack Vector for Your Secrets
01:57 - Supply Chain Vetting: How to Source Trusted MCP Servers
02:53 - Scoped Tokens and the "Auto-Run" Security Trap
03:50 - The Postmark Incident: How Version 16 Stole Everything
04:57 - Runtime Hardening: Auditing Input Schemas and Disabling Unused Tools
05:50 - Permission Gatekeeping: Preventing Data Leakage via Prompts
06:13 - Post-Usage Cleanup: Revoking Keys and Git History Audits
06:57 - The Final MCP Security Checklist
βοΈ This talk was part of AI Coding Summit 2026:
Hands-On Guide to Secure AI-Driven Coding | Gil Friedman
π aicodingsummit.com/?utm_source=youtube&utm_medium=GilFriedman
π Weβve hidden a secret code for 20% off your next event.
Join our upcoming conferences!
π« JSNation 2026 June 11, 2026 (Amsterdam)
πjsnation.com/?utm_source=youtube&utm_medium=GilFriedman
π« React Summit, June 12, 2026 (Amsterdam)
reactsummit.com/?utm_source=youtube&utm_medium=GilFriedman
π« TechLeadConf, June 11, 2026 (Amsterdam)
techleadconf.com/?utm_source=youtube&utm_medium=GilFriedman
π« Node Congress, March 26 & 27, 2026 (Online)
nodecongress.com/?utm_source=youtube&utm_medium=GilFriedman
and more!
π Check out all the upcoming events from GitNation:
π gitnation.com/events?utm_source=youtube&utm_medium=GilFriedman
Don't forget to use INSIDER20 promo code for 20% off on tickets.
#MCP #ModelContextProtocol #Cybersecurity #AIAgents #AppSec #SupplyChainAttack #DataExfiltration #ProductionSecurity #DevSecOps #SecOps #InfoSec #AIArchitecture #BackslashSecurity #GitNation #LLMSecurity #TechTalk #Engineering #API #MaliciousUpdate #VulnerabilityManagement #CyberThreats #CloudSecurity #SoftwareEngineering
Think Model Context Protocol (MCP) is secure by default? No βοΈ Learn the exact framework for selecting and configuring AI agent tools to prevent a 1-line production hijack.
π Giving AI agents "hands and legs" means granting permissions to read files, execute commands, and handle sensitive API keys that can be hijacked by malicious actors. Standard security layers fail to detect supply chain attacks hidden in legitimate tool updates.
In this technical deep-dive, Gil Friedman (Field CTO at Backslash Security) dissects the Model Context Protocol lifecycle and reveals the framework for hardening AI-to-tool connections against unauthorized actions π«
π₯ Gil Friedman is the Field CTO at Backslash Security, specializing in cloud-native AppSec and the security of AI-driven development. With a background leading core engineering teams at Meta and SAP/Concur, he focuses on hardening AI agent workflows and securing the Model Context Protocol (MCP) against sophisticated supply chain attacks in production environments.
π Connect with Gil:
π linkedin.com/in/gilfr
π Learn more about Backslash Security:
π https://www.backslash.security/
π Follow the link to watch the full version of the talk and gain access to all AI Coding Summit recordings:
π gitnation.com/events/ai-coding-summit-2026?utm_source=youtube&utm_medium=GilFriedman
π Timestamps:
00:00 - Giving AI "Hands and Legs": The Power of MCP
00:51 - Why MCP is a Massive Attack Vector for Your Secrets
01:57 - Supply Chain Vetting: How to Source Trusted MCP Servers
02:53 - Scoped Tokens and the "Auto-Run" Security Trap
03:50 - The Postmark Incident: How Version 16 Stole Everything
04:57 - Runtime Hardening: Auditing Input Schemas and Disabling Unused Tools
05:50 - Permission Gatekeeping: Preventing Data Leakage via Prompts
06:13 - Post-Usage Cleanup: Revoking Keys and Git History Audits
06:57 - The Final MCP Security Checklist
βοΈ This talk was part of AI Coding Summit 2026:
Hands-On Guide to Secure AI-Driven Coding | Gil Friedman
π aicodingsummit.com/?utm_source=youtube&utm_medium=GilFriedman
π Weβve hidden a secret code for 20% off your next event.
Join our upcoming conferences!
π« JSNation 2026 June 11, 2026 (Amsterdam)
πjsnation.com/?utm_source=youtube&utm_medium=GilFriedman
π« React Summit, June 12, 2026 (Amsterdam)
reactsummit.com/?utm_source=youtube&utm_medium=GilFriedman
π« TechLeadConf, June 11, 2026 (Amsterdam)
techleadconf.com/?utm_source=youtube&utm_medium=GilFriedman
π« Node Congress, March 26 & 27, 2026 (Online)
nodecongress.com/?utm_source=youtube&utm_medium=GilFriedman
and more!
π Check out all the upcoming events from GitNation:
π gitnation.com/events?utm_source=youtube&utm_medium=GilFriedman
Don't forget to use INSIDER20 promo code for 20% off on tickets.
#MCP #ModelContextProtocol #Cybersecurity #AIAgents #AppSec #SupplyChainAttack #DataExfiltration #ProductionSecurity #DevSecOps #SecOps #InfoSec #AIArchitecture #BackslashSecurity #GitNation #LLMSecurity #TechTalk #Engineering #API #MaliciousUpdate #VulnerabilityManagement #CyberThreats #CloudSecurity #SoftwareEngineering










