# Discovering & Securing Your AI Agent Attack Surface - Jeremy Snyder - ASW #391 Page: https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755/discovering-securing-your-ai-agent-attack-surface-jeremy-snyder-asw-391 Text version: https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755/discovering-securing-your-ai-agent-attack-surface-jeremy-snyder-asw-391.md Podcast: [Security Weekly Podcast Network (Audio)](https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755) Published: 2026-07-14T09:00:00+00:00 Episode link: http://sites.libsyn.com/18678/discovering-securing-your-ai-agent-attack-surface-jeremy-snyder-asw-391 Audio file: https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/pauldotcom/ASW_391_1--b923eabc-93ec-481b-b200-9712afc64bbb--audio-converted--842a0eae-dff5-44a7-a6d1-43f6f626e610.mp3?dest-id=13427 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/security-weekly-podcast-network-audio-319755/episodes/discovering-securing-your-ai-agent-attack-surface-jeremy-snyder-asw-391 Duration seconds: 4049 ## Resource While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order to help orgs understand and prioritize their attack surface. A lot of orgs don't have to deal with model-specific threats or building their own GPU architecture, but every org adopting LLMs and agents should be aware of how those agents are being invoked and the output those agents are producing. That awareness of input and output helps in identifying and mitigating prompt injection attacks, ensuring agents are working within their expected boundaries, and taming token budgets. Resources: https://genai.owasp.org/llm-top-10/ https://github.com/rtk-ai/rtk https://docs.aws.amazon.com/bedrock/latest/userguide/prompt-caching.html https://www.firetail.ai/blog/beyond-the-spectacle-rsac-2026-and-the-5-layers-of-ai-security Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-391 ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/security-weekly-podcast-network-audio-319755/episodes/discovering-securing-your-ai-agent-attack-surface-jeremy-snyder-asw-391/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/security-weekly-podcast-network-audio-319755/discovering-securing-your-ai-agent-attack-surface-jeremy-snyder-asw-391.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.