When AI Agents Become the Supply Chain: Hidden Control Planes in Agentic Systems

Wednesday, August 12, 2026
11:30 AM - 12:00 PM
AI Risk Summit Tech Track (Salon II)

About This Session

Agentic AI risk is no longer only prompt injection. Once assistants can read repositories, browse pages, load plugins, install dependencies, and call tools, the real security boundary moves into the control plane around the model.
This session maps that boundary through three concrete failure modes from recent research: repository instruction files that silently steer coding agents, marketplace skills and plugins that alter dependency installation, and agentic browser/runtime patterns where untrusted content becomes model context and tool execution.
Attendees will leave with a practical threat model for agentic systems: content ingestion, context translation, tool authority, dependency provenance, and runtime containment. The session will also cover defensive controls security leaders can apply now, including instruction provenance, allowlisted tools, permission gates, dependency-source enforcement, audit logs, and review workflows for agent behavior.
This is an educational, vendor-neutral session for CISOs, AppSec teams, AI platform owners, and developers adopting coding assistants or autonomous agents. The examples come from real research into agentic AI and AI coding-assistant behavior, but the talk focuses on repeatable risk patterns rather than any single product.

Learning objectives:
1. Recognize hidden instruction sources that can steer agent behavior.
2. Explain why agentic AI risk resembles supply-chain and control-plane security.
3. Identify practical controls that reduce the blast radius of AI agents in enterprise environments.

Speaker

David Abutbul

David Abutbul

AI Security Researcher - Prompt Security, a SentinelOne company

David Abutbul is an AI Security Researcher at Prompt Security, a SentinelOne company. His work focuses on agentic AI attack surfaces, AI coding-assistant security, prompt injection, tool abuse, and practical AI red teaming. He has published blogs researching hidden repository instructions, marketplace skill dependency hijacking, agentic runtime boundaries, and red-teaming real-world AI systems. David turns hands-on security research into practical guidance for defenders adopting AI systems.