Most agent security content shows you a policy file. On July 28 we show you an attack.
The setup: an AI agent runs a real workflow with real credentials in play. API calls, tool execution, file access. Every credential is brokered per invocation from a SPIFFE workload identity: injected by a broker the agent cannot reach, used once, zeroed from memory after use. Every operation lands in a tamper-evident audit trail, hash-chained from the policy decision down to the syscall.
Then we attack it. Live, against the running system, while you watch.
Aleksy Siek, founding maintainer of nono, runs the full flow end to end: creating a profile from scratch, wiring up a credential, inspecting the audit trail as it records every move, and then live escape and attack attempts against the running sandbox. You see what the attacker sees, what the policy engine decides, and what the log records. No slides standing in for software. If something breaks, you see that too.
If you have been following the SPIFFE and workload identity conversation, this is where you see it run.
nono is an Apache-2.0 per-invocation capability broker for agentic AI systems: 3k+ stars, 70+ contributors, and the reference implementation for SAF-M-74, the OpenSSF/Linux Foundation standard for per-invocation capability brokering. This is what it looks like running.
Tuesday July 28, 4pm UK / 11am ET. Free, streamed live.
Register at luma.com/73tz35ak. The stream link goes straight to registrants. Bring questions: we take them live.
This post is part of a series on agent infrastructure that assumes compromise. The thesis, and where it leads: Assume the agent is compromised. Now what?