Secure MCP Setup: Why Standard AI Agents are a Production Hijack Risk @JavaScriptConferences
Secure MCP Setup: Why Standard AI Agents are a Production Hijack Risk  @JavaScriptConferences
Uploaded March 2026 | Updated September 2026, 2 weeks ago
Think Model Context Protocol (MCP) is secure by default? No ⛔️ Learn the exact framework for selecting and configuring AI agent tools to prevent a 1-line production hijack.

πŸ›‘ Giving AI agents "hands and legs" means granting permissions to read files, execute commands, and handle sensitive API keys that can be hijacked by malicious actors. Standard security layers fail to detect supply chain attacks hidden in legitimate tool updates.

In this technical deep-dive, Gil Friedman (Field CTO at Backslash Security) dissects the Model Context Protocol lifecycle and reveals the framework for hardening AI-to-tool connections against unauthorized actions πŸ’«

πŸ”₯ Gil Friedman is the Field CTO at Backslash Security, specializing in cloud-native AppSec and the security of AI-driven development. With a background leading core engineering teams at Meta and SAP/Concur, he focuses on hardening AI agent workflows and securing the Model Context Protocol (MCP) against sophisticated supply chain attacks in production environments.
πŸ‘‰ Connect with Gil:
πŸ”— linkedin.com/in/gilfr
πŸ‘‰ Learn more about Backslash Security:
πŸ”— https://www.backslash.security/

πŸ“Œ Follow the link to watch the full version of the talk and gain access to all AI Coding Summit recordings:
πŸ”— gitnation.com/events/ai-coding-summit-2026?utm_source=youtube&utm_medium=GilFriedman

πŸ• Timestamps:
00:00 - Giving AI "Hands and Legs": The Power of MCP
00:51 - Why MCP is a Massive Attack Vector for Your Secrets
01:57 - Supply Chain Vetting: How to Source Trusted MCP Servers
02:53 - Scoped Tokens and the "Auto-Run" Security Trap
03:50 - The Postmark Incident: How Version 16 Stole Everything
04:57 - Runtime Hardening: Auditing Input Schemas and Disabling Unused Tools
05:50 - Permission Gatekeeping: Preventing Data Leakage via Prompts
06:13 - Post-Usage Cleanup: Revoking Keys and Git History Audits
06:57 - The Final MCP Security Checklist

✍️ This talk was part of AI Coding Summit 2026:
Hands-On Guide to Secure AI-Driven Coding | Gil Friedman
πŸ”— aicodingsummit.com/?utm_source=youtube&utm_medium=GilFriedman

πŸ“Œ We’ve hidden a secret code for 20% off your next event.
Join our upcoming conferences!

πŸ’« JSNation 2026 June 11, 2026 (Amsterdam)
πŸ”—jsnation.com/?utm_source=youtube&utm_medium=GilFriedman

πŸ’« React Summit, June 12, 2026 (Amsterdam)
reactsummit.com/?utm_source=youtube&utm_medium=GilFriedman

πŸ’« TechLeadConf, June 11, 2026 (Amsterdam)
techleadconf.com/?utm_source=youtube&utm_medium=GilFriedman

πŸ’« Node Congress, March 26 & 27, 2026 (Online)
nodecongress.com/?utm_source=youtube&utm_medium=GilFriedman

and more!

πŸš€ Check out all the upcoming events from GitNation:
πŸ”— gitnation.com/events?utm_source=youtube&utm_medium=GilFriedman

Don't forget to use INSIDER20 promo code for 20% off on tickets.

#MCP #ModelContextProtocol #Cybersecurity #AIAgents #AppSec #SupplyChainAttack #DataExfiltration #ProductionSecurity #DevSecOps #SecOps #InfoSec #AIArchitecture #BackslashSecurity #GitNation #LLMSecurity #TechTalk #Engineering #API #MaliciousUpdate #VulnerabilityManagement #CyberThreats #CloudSecurity #SoftwareEngineering
Secure MCP Setup: Why Standard AI Agents are a Production Hijack RiskπŸš€ The next edition of AI Coding Summit lands on Feb 26-27! Grab your ticket πŸ‘‰ aicodingsummit.comStop adopting new tech | A strategy to save engineering timeAI Coding Summit 2026: Adding a new dimension in London! πŸ›© #shortsA JS Devs Guide to Not Dismissing BlockchainMCP Apps: The Spec Behind Imagine, ChatGPT Apps and Shopify | Liad Yosef & Ido SalomonYour Node.js App Cant Monitor Itself. Matteo Collina on the Architecture That Fixes It❌ Stop playing with prompts. Start building systems πŸ›  #shortsHow to Architect & Scale Production Web Systems in 2026 | Web Engineering Summit | Tech ConferenceDo we really know the age of the language we use every day? 😨 #shortsJS Tooling in 2026: Fast runtimes, strict structures, or AI-powered workflows? πŸ› οΈβš‘οΈ #shortsJSNation 2024 Aftermovie - The Main JavaScript Conference of 2024
JavaScript Conferences by GitNation |

Secure MCP Setup: Why Standard AI Agents are a Production Hijack Risk

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER