Skip to main content

Snyk Labs

Featured article

Why Threat Modeling is the Best Defense for AI Agents

Headshot of Joe Bollen

Joe Bollen


Imagine an agent that reads your email, pulls context from internal docs, and drafts replies. No memory-unsafe code. No SQL injection flaws. No suspicious endpoints. The permissions are valid. The tool calls are legitimate.

And it can still be compromised by a single sentence.

We are witnessing a fundamental shift in application security. Traditional tooling is built to find bugs in deterministic code. But generative AI systems do not fail at the level of code. They fail at the level of behavior.

In the deterministic world, we "solved" whole classes of security problems by enforcing hard boundaries. SQL injection became manageable because we could parameterise queries, separating "instructions" from "data." If your input remained data, the trust boundary held. With agentic AI, that trust boundary has dissolved.


Latest Demos and Research

Featured Video

Vibe Coding with Claude Agentic AI Tool

Experiments

Where security meets curiosity

Explore projects from Snyk Labs

ai-bom-scan

Python

A tool to scan Snyk AI-BOMs for specific components in Snyk organizations

December 16, 2025


8

6

0

ai-promoter

Python

A simple web application that makes it easy for employees at your company to see and promote content you're creating!

October 30, 2025


3

0

0

mcp-server-nodejs-api-docs

JavaScript

MCP Server for the Node.js API documentation

August 18, 2025


4

2

0