Conference50min
Toxic Flows in MCP Servers and Skills: What Your Agent Blindly Trusts
This talk introduces “toxic flows” in AI agent stacks: trust paths through MCP servers and Skills that can leak context, manipulate decisions, and trigger unintended actions. It shows how trust failures arise, parallels familiar software risks, and offers a framework for identifying boundaries and hardening agent integrations.
talk.summaryAiDisclaimer
Brian VermeerSnyk
talkDetail.whenAndWhere
Thursday, October 8, 09:30-10:20
TBA 6
talks.roomOccupancytalks.noOccupancyInfo
AI agents don't just trust MCP servers. They trust Skills too. Both are attack surfaces, yet most teams treat neither as part of the same trust model.
In this talk, we introduce toxic flows: trust paths through an agent stack where tool descriptions, MCP responses, and Skill definitions can leak sensitive context, manipulate agent decisions, and trigger unintended actions without the model violating a single instruction. We demonstrate this live.
This session is not about adding authentication or wrapping everything in TLS. It's about understanding how trust failures emerge, how they mirror familiar software risks like dependency confusion and unsafe deserialization, and how to design MCP servers and Skill integrations that reduce trust, contain blast radius, and keep agent systems defensible.
Attendees will leave with a practical framework for identifying trust boundaries, evaluating agent integrations, and hardening their AI stack against toxic flows.
In this talk, we introduce toxic flows: trust paths through an agent stack where tool descriptions, MCP responses, and Skill definitions can leak sensitive context, manipulate agent decisions, and trigger unintended actions without the model violating a single instruction. We demonstrate this live.
This session is not about adding authentication or wrapping everything in TLS. It's about understanding how trust failures emerge, how they mirror familiar software risks like dependency confusion and unsafe deserialization, and how to design MCP servers and Skill integrations that reduce trust, contain blast radius, and keep agent systems defensible.
Attendees will leave with a practical framework for identifying trust boundaries, evaluating agent integrations, and hardening their AI stack against toxic flows.
Brian Vermeer
Staff Developer Advocate for Snyk, Java Champion, Oracle Ace Pro, and Software Engineer with over a decade of hands-on experience in creating and maintaining software. He is passionate about Java, (Pure) Functional Programming and Cybersecurity. Brian is a JUG leader for the Virtual JUG and the NLJUG. He also co-leads the DevSecCon community and is a community manager for Foojay. He is a regular international speaker on mostly Java-related conferences like JavaOne, Devnexus, Devoxx, Jfokus, JavaZone and many more. Besides all that, Brian is a military reserve for the Royal Netherlands Air Force and a Taekwondo Master / Teacher.