What this video shows
Patterson explains the lethal trifecta as access to private data, exposure to attacker-controlled content, and a channel for external communication. A laptop coding agent can combine all three through source files, issues or web pages, stored credentials, shell access, and network requests.
He proposes remote development environments, restricted networking, a model proxy that logs or redacts traffic, and process-level command controls. These controls can reduce reach and improve evidence, but they do not prove that an agent is safe. Learnetto recommends removing at least one part of the trifecta, minimizing credentials, separating untrusted content from consequential actions, and requiring approval for writes.
Read Simon Willison's original lethal-trifecta threat model for the private-data, untrusted-content, and external-communication definition. Use OWASP's Agentic AI threat guidance to broaden the review beyond prompt injection.
What you will learn
- An agent that combines private data, untrusted input, and external communication can expose data through prompt injection.
- Keep agent credentials narrower than a developer's normal interactive session whenever possible.
- Network and command allowlists reduce possible actions, while logs help reviewers reconstruct what occurred.
- Human approval matters most at the boundary where an untrusted input could trigger a consequential action.
How to apply this safely
- List every private data source, untrusted input, outbound channel, credential, and destructive command available to the agent.
- Remove unnecessary access and place remaining work in an isolated environment with short-lived credentials.
- Restrict network destinations and commands, then test indirect prompt injections from files, issues, dependencies, and web content.
- Require review for writes and keep tamper-resistant logs, expiration, incident response, and a reliable way to stop the session.
Important limitations
- Patterson works for Coder and recommends architecture that can support Coder's product. The talk provides a threat model and design advice rather than measured attack-prevention rates.
- A model proxy or command filter can miss encoded data, novel tools, allowed-domain abuse, and actions that appear benign in isolation.
Sources to check
- The lethal trifecta for AI agents Original threat-model definition and prompt-injection explanation.
- OWASP Top 10 for Agentic Applications Primary agent-security guidance for threats and mitigations.
Continue learning on Learnetto
Best coding-agent courses
Combine coding workflows with explicit permissions and review.
Best AI agent evaluation courses
Create adversarial cases and trace-based security checks.
AI evals guide
Add security failures to versioned regression suites.