Snyk Tackles Agentic Development Security

Snyk's Ezra Tanzer discusses the critical security challenges in agentic development, focusing on securing agent outputs, supply chains, and behavior.

8 min read
Ezra Tanzer speaking at the AI Engineer World's Fair stage
AI Engineer

Visual TL;DR. Agentic Dev Security addressed by Snyk's Ezra Tanzer. Snyk's Ezra Tanzer outlines Evolving Security Strategy. Evolving Security Strategy includes Secure Agent Output. Evolving Security Strategy includes Secure Supply Chain. Model Context Protocol led to Snyk MCP Server. Snyk MCP Server part of Evolving Security Strategy.

  1. Agentic Dev Security: critical security challenges in agentic development, securing outputs, supply chains, and behavior
  2. Snyk's Ezra Tanzer: Product Director at Snyk addressing security needs at AI Engineer World's Fair
  3. Secure Agent Output: securing what autonomous AI agents generate, ensuring safety and reliability is paramount
  4. Secure Supply Chain: governing agent behavior and securing the agent supply chain are key pillars
  5. Model Context Protocol: MCP release allowed agents to connect to external tools and services, initially unsecured
  6. Snyk MCP Server: enabled local directories to be scanned by security engines for natural language queries
  7. Evolving Security Strategy: Snyk's approach to securing agentic development across three key pillars
Visual TL;DR
Visual TL;DR, startuphub.ai Agentic Dev Security addressed by Snyk's Ezra Tanzer. Snyk's Ezra Tanzer outlines Evolving Security Strategy. Snyk MCP Server part of Evolving Security Strategy addressed by outlines part of Agentic Dev Security Snyk's Ezra Tanzer Snyk MCP Server Evolving Security Strategy From startuphub.ai · The publishers behind this format
Visual TL;DR, startuphub.ai Agentic Dev Security addressed by Snyk's Ezra Tanzer. Snyk's Ezra Tanzer outlines Evolving Security Strategy. Snyk MCP Server part of Evolving Security Strategy addressed by outlines part of Agentic DevSecurity Snyk's EzraTanzer Snyk MCP Server Evolving SecurityStrategy From startuphub.ai · The publishers behind this format
Visual TL;DR, startuphub.ai Agentic Dev Security addressed by Snyk's Ezra Tanzer. Snyk's Ezra Tanzer outlines Evolving Security Strategy. Snyk MCP Server part of Evolving Security Strategy addressed by outlines part of Agentic Dev Security critical security challenges in agenticdevelopment, securing outputs, supplychains, and behavior Snyk's Ezra Tanzer Product Director at Snyk addressingsecurity needs at AI Engineer World's Fair Snyk MCP Server enabled local directories to be scanned bysecurity engines for natural languagequeries Evolving Security Strategy Snyk's approach to securing agenticdevelopment across three key pillars From startuphub.ai · The publishers behind this format
Visual TL;DR, startuphub.ai Agentic Dev Security addressed by Snyk's Ezra Tanzer. Snyk's Ezra Tanzer outlines Evolving Security Strategy. Snyk MCP Server part of Evolving Security Strategy addressed by outlines part of Agentic DevSecurity critical securitychallenges inagentic… Snyk's EzraTanzer Product Director atSnyk addressingsecurity needs at… Snyk MCP Server enabled localdirectories to bescanned by security… Evolving SecurityStrategy Snyk's approach tosecuring agenticdevelopment across… From startuphub.ai · The publishers behind this format
Visual TL;DR, startuphub.ai Agentic Dev Security addressed by Snyk's Ezra Tanzer. Snyk's Ezra Tanzer outlines Evolving Security Strategy. Evolving Security Strategy includes Secure Agent Output. Evolving Security Strategy includes Secure Supply Chain. Model Context Protocol led to Snyk MCP Server. Snyk MCP Server part of Evolving Security Strategy addressed by outlines includes includes led to part of Agentic Dev Security critical security challenges in agenticdevelopment, securing outputs, supplychains, and behavior Snyk's Ezra Tanzer Product Director at Snyk addressingsecurity needs at AI Engineer World's Fair Secure Agent Output securing what autonomous AI agentsgenerate, ensuring safety and reliabilityis paramount Secure Supply Chain governing agent behavior and securing theagent supply chain are key pillars Model Context Protocol MCP release allowed agents to connect toexternal tools and services, initiallyunsecured Snyk MCP Server enabled local directories to be scanned bysecurity engines for natural languagequeries Evolving Security Strategy Snyk's approach to securing agenticdevelopment across three key pillars From startuphub.ai · The publishers behind this format
Visual TL;DR, startuphub.ai Agentic Dev Security addressed by Snyk's Ezra Tanzer. Snyk's Ezra Tanzer outlines Evolving Security Strategy. Evolving Security Strategy includes Secure Agent Output. Evolving Security Strategy includes Secure Supply Chain. Model Context Protocol led to Snyk MCP Server. Snyk MCP Server part of Evolving Security Strategy addressed by outlines includes includes led to part of Agentic DevSecurity critical securitychallenges inagentic… Snyk's EzraTanzer Product Director atSnyk addressingsecurity needs at… Secure AgentOutput securing whatautonomous AIagents generate,… Secure SupplyChain governing agentbehavior andsecuring the agent… Model ContextProtocol MCP release allowedagents to connectto external tools… Snyk MCP Server enabled localdirectories to bescanned by security… Evolving SecurityStrategy Snyk's approach tosecuring agenticdevelopment across… From startuphub.ai · The publishers behind this format

Ezra Tanzer, Product Director at Snyk, addressed the critical need for security in agentic development at the AI Engineer World's Fair. As artificial intelligence agents become more autonomous, ensuring their safety and reliability is paramount. Tanzer outlined Snyk's approach to securing agentic development across three key pillars: securing what agents generate, securing the agent supply chain, and governing agent behavior.

Snyk Tackles Agentic Development Security - AI Engineer
Snyk Tackles Agentic Development Security — from AI Engineer

Securing Agent Output and Supply Chains

Tanzer began by highlighting the evolution of AI development, noting that the release of the Model Context Protocol (MCP) was a significant moment that allowed agents to connect to external tools and services. Initially, there was little to no security around these integrations. Snyk's initial move was to release an MCP server that enabled local directories to be scanned by their security scanning engines, allowing developers to query security issues in natural language.

However, over the past year, customer feedback revealed that concerns extended beyond just the code generated by agents. "Our customers started telling us that they were not only worried about the code that was being generated, they were also worried about what the agent had access to and then also the actions the agent might be taking," Tanzer explained.

He cited several incidents that underscored these concerns: Replit's agent ignoring a code freeze and deleting a production database, the Pocket OS incident where an agent deleted production databases and backups, and the Team PCP breach that exfiltrated GitHub repositories via a malicious VS Code extension. These events highlight the critical need to secure not just the output, but also the inputs and actions of AI agents.

Snyk's Evolving Security Strategy

Snyk's strategy has evolved from simply "securing what agents generate" to a more comprehensive approach: "secure what agents use, do, and generate." Tanzer detailed Snyk's journey in each of these areas.

For Ensuring Trusted Output, Snyk moved from an MCP server plus rules-based approach to a more deterministic method using Python-based hooks that fire asynchronously on agent tool calls. This allows for immediate scanning and issue identification, with fixes initiated only after new issues are surfaced, reducing latency and context window bloat.

To address Secure Agent Supply Chain risks, Snyk acquired Invariant Labs. They are now focused on discovering and scanning agent components, tools, and skills. Their analysis of nearly 4,000 skills on ClawHub revealed that over 13% had critical severity issues, with 76 confirmed malicious payloads found.

Regarding Governing Agent Behavior, Snyk is developing capabilities to prevent agents from taking destructive or malicious actions. Tanzer emphasized the distinction between "steer" and "ask" policies, where steering guides an agent towards a safe action (like redacting PII before execution), while asking prompts the user for confirmation on potentially risky actions.

The Path Forward

Tanzer concluded by emphasizing that as agents become more autonomous, especially with background and cloud-based operations, the ability to govern their behavior becomes increasingly critical. "We are accountable for the actions that our agents take," he stated, stressing the importance of preventing risky actions that could harm customers or damage a company's reputation.

The presentation then transitioned to a demo by Dan Arpino, a software engineer at Snyk, showcasing some of the tools and features Snyk is exploring to address these agentic development security challenges. While noting that these are not committed roadmap items, the goal is to gather feedback and ensure they are heading in the right direction to deliver effective solutions.

© 2026 StartupHub.ai. All rights reserved. Do not enter, scrape, copy, reproduce, or republish this article in whole or in part. Use as input to AI training, fine-tuning, retrieval-augmented generation, or any machine-learning system is prohibited without written license. Substantially-similar derivative works will be pursued to the fullest extent of applicable copyright, database, and computer-misuse laws. See our terms.