<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/through-the-ai-fog-the-architectural-decision-agentic-security-depends-on-manoj-nair-snyk-gxuswcxwg" -->

---
title: Through the AI Fog: The Architectural Decision Agentic...
description: Manoj Nair, Snyk&#x27;s CTO and Chief Innovation Officer, presents real-world data on the security challenges emerging from agentic AI development. Key findings...
canonical: https://daily.dev/posts/through-the-ai-fog-the-architectural-decision-agentic-security-depends-on-manoj-nair-snyk-gxuswcxwg
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk | daily.dev
og:description: Manoj Nair, Snyk&#x27;s CTO and Chief Innovation Officer, presents real-world data on the security challenges emerging from agentic AI development. Key findings...
og:url: https://daily.dev/posts/through-the-ai-fog-the-architectural-decision-agentic-security-depends-on-manoj-nair-snyk-gxuswcxwg
og:image: https://api.daily.dev/og/posts/gXUSwcxwg.png
og:image:alt: Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk

**[AI Engineer](https://daily.dev/sources/aidotengineer)** · 23 min read · 0 upvotes · 0 comments

## Summary

Manoj Nair, Snyk's CTO and Chief Innovation Officer, presents real-world data on the security challenges emerging from agentic AI development. Key findings include a 108% growth in enterprise vulnerability backlogs, evidence that AI-generated code is slightly worse than human-written code, and that over a third of AI skills/tools contain malware or vulnerabilities. A central architectural argument is made that the generator and validator in AI systems should not be the same — LLMs alone are inconsistent security validators, finding only 50% of vulnerabilities across repeated runs with an F1 score of 40%. The talk covers threats from MCP server exploits, toxic skills, uncontrolled agent behavior (e.g., agents copying PII to untrusted databases), and the difficulty of governing AI components you don't know exist. Snyk demos its package health checking tool integrated into Claude/Codex workflows and a skill/MCP risk assessment tool, and introduces its Evo agentic security platform.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.youtube.com/watch?v=1EZdpEhwmNc>

## Questions this post answers

### Why can't the same AI model be both the code generator and the security validator?

Because generator and validator models share the same blind spots and inconsistencies, undermining trust in autonomous verification. In one benchmark, the latest models found the same known vulnerability only 50% of the time across five repeated runs and achieved just a 75% detection rate with a 40% F1 score compared to a deterministic check, indicating LLM-only scanning cannot reliably replace separate validation.

_Teams weighing whether to trust AI-only code review follow findings like this on daily.dev before shipping agentic workflows._

### How risky are AI agent skills and MCP servers in production environments?

They carry significant risk: research cited found that more than a third of publicly available agent skills contain malware or vulnerabilities, and some skills load instructions from external YAML files hosted online, meaning the skill's logic can change without the skill file itself changing. Enterprises have responded by shutting down MCP servers entirely before cautiously re-enabling them with monitoring.

_Engineers vetting third-party skills and MCP servers can track this kind of agent-security research on daily.dev._

### Do frontier AI models resist prompt injection attacks that try to extract personal information or override decisions?

Resistance varies widely by model and attack type. In red-team testing, established frontier models showed 0% successful PII extraction, while a newer widely-discussed model had a 100% extraction success rate under the same attacks; conversely, on a decision-override test, the frontier models performed worse than an open model, which had a 0% override success rate.

_Developers choosing which model to trust with sensitive data can follow this kind of adversarial testing on daily.dev._

## Similar posts on daily.dev

- [The New Security Risks of Agentic Development](https://daily.dev/posts/the-new-security-risks-of-agentic-development-rjskp1wg4) · Snyk · 1 upvotes · 0 comments
- [Old AI Security vs Evo: Watch Agentic Security Replace Weeks of Manual Work](https://daily.dev/posts/old-ai-security-vs-evo-watch-agentic-security-replace-weeks-of-manual-work-emwvtnvqt) · Snyk · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#mcp](https://daily.dev/tags/mcp), [#ai-security](https://daily.dev/tags/ai-security), [#agentic-ai](https://daily.dev/tags/agentic-ai)

[View this post on daily.dev](https://daily.dev/posts/through-the-ai-fog-the-architectural-decision-agentic-security-depends-on-manoj-nair-snyk-gxuswcxwg)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk","url":"https://daily.dev/posts/through-the-ai-fog-the-architectural-decision-agentic-security-depends-on-manoj-nair-snyk-gxuswcxwg","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/through-the-ai-fog-the-architectural-decision-agentic-security-depends-on-manoj-nair-snyk-gxuswcxwg"},"datePublished":"2026-07-20T17:41:33.060Z","dateModified":"2026-09-14T08:20:39.464Z","description":"Manoj Nair, Snyk's CTO and Chief Innovation Officer, presents real-world data on the security challenges emerging from agentic AI development. Key findings...","image":"https://i.ytimg.com/vi/1EZdpEhwmNc/sddefault.jpg","thumbnailUrl":"https://i.ytimg.com/vi/1EZdpEhwmNc/sddefault.jpg","isAccessibleForFree":true,"articleSection":"AI Engineer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"AI Engineer","logo":"https://media.daily.dev/image/upload/s--u5PucxNT--/f_auto/v1724338940/logos/aidotengineer","url":"https://daily.dev/sources/aidotengineer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/through-the-ai-fog-the-architectural-decision-agentic-security-depends-on-manoj-nair-snyk-gxuswcxwg","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,mcp,ai-security,agentic-ai","timeRequired":"PT23M","video":{"@type":"VideoObject","name":"Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk","description":"Manoj Nair, Snyk's CTO and Chief Innovation Officer, presents real-world data on the security challenges emerging from agentic AI development. Key findings...","thumbnailUrl":"https://i.ytimg.com/vi/1EZdpEhwmNc/sddefault.jpg","uploadDate":"2026-07-20T17:41:33.060Z","duration":"PT23M","url":"https://api.daily.dev/r/gXUSwcxwg","embedUrl":"https://www.youtube.com/embed/1EZdpEhwmNc"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"AI Engineer","item":"https://daily.dev/sources/aidotengineer"},{"@type":"ListItem","position":3,"name":"Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/through-the-ai-fog-the-architectural-decision-agentic-security-depends-on-manoj-nair-snyk-gxuswcxwg#faq","mainEntity":[{"@type":"Question","name":"Why can't the same AI model be both the code generator and the security validator?","acceptedAnswer":{"@type":"Answer","text":"Because generator and validator models share the same blind spots and inconsistencies, undermining trust in autonomous verification. In one benchmark, the latest models found the same known vulnerability only 50% of the time across five repeated runs and achieved just a 75% detection rate with a 40% F1 score compared to a deterministic check, indicating LLM-only scanning cannot reliably replace separate validation. Teams weighing whether to trust AI-only code review follow findings like this on daily.dev before shipping agentic workflows."}},{"@type":"Question","name":"How risky are AI agent skills and MCP servers in production environments?","acceptedAnswer":{"@type":"Answer","text":"They carry significant risk: research cited found that more than a third of publicly available agent skills contain malware or vulnerabilities, and some skills load instructions from external YAML files hosted online, meaning the skill's logic can change without the skill file itself changing. Enterprises have responded by shutting down MCP servers entirely before cautiously re-enabling them with monitoring. Engineers vetting third-party skills and MCP servers can track this kind of agent-security research on daily.dev."}},{"@type":"Question","name":"Do frontier AI models resist prompt injection attacks that try to extract personal information or override decisions?","acceptedAnswer":{"@type":"Answer","text":"Resistance varies widely by model and attack type. In red-team testing, established frontier models showed 0% successful PII extraction, while a newer widely-discussed model had a 100% extraction success rate under the same attacks; conversely, on a decision-override test, the frontier models performed worse than an open model, which had a 0% override success rate. Developers choosing which model to trust with sensitive data can follow this kind of adversarial testing on daily.dev."}}]}
```

