AI Security Engineer Foundations + Certificate - Micah Silverman, Snyk

AI Engineer2h
0 comments · 0 votesOpen discussionClose discussion
Sign in to join the discussion

    Video summary

    Micah Silverman introduces an accelerated AI security curriculum covering prompt injection, sensitive-data exposure, supply-chain risks and poisoning. His central distinction is between telling a model what not to do and enforcing what the application can access. Limiting available data, keeping secrets outside prompts and validating downstream outputs remain part of a layered design.

    The shadow-AI module turns inventory into a governance mechanism. An AI bill of materials records models, datasets, dependencies and tools so policy changes can be detected alongside software changes. Silverman's Snyk Evo demonstration creates a model policy and surfaces a matching issue; the separate CI-baseline comparison is explained but not demonstrated in the session.

    Threat modeling follows assets, data flows and trust boundaries through retrieval, context construction and external actions. The MCP section separates malicious tool descriptions from vulnerable server code, showing how both model-facing instructions and ordinary software dependencies can introduce risk. These are related attack surfaces rather than problems solved by a single prompt or scanner.

    The agentic-development section argues for isolated environments, narrow privileges, reviewed changes and supply-chain checks. Silverman ends with an authorized capture-the-flag chatbot exercise that illustrates the difference between restricted information awareness and disclosure. The live attempts do not retrieve the protected grades or complete the flag, so the recording is not evidence of a successful jailbreak.

    Original YouTube thumbnailWatch on YouTube

    Share this page

    Portraits of Micah Silverman against black with the headline AI SECURITY FOUNDATIONS in attention blue and white. Framed in blue with WWW.ARTIFICIAL-INTELLIGENCE.VIDEO, 11 October 2026 and duration 2h.

    Micah Silverman connects familiar application-security controls to AI risks, emphasizing that prompts cannot enforce permissions and that inventories, threat models and restricted agent access must work together.