Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Liran Tal :verified:

@lirantal@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

🌟 GitHub Star 2022
🏆 OpenJS Pathfinder award for Security 2022
🥑 DevRel at @snyksec
@NodeJS AppSec & OpenSource ❤️
O'Reilly author on Serverless JavaScript Security
Docker container security hero 🐳

Author of Node.js Security 👉 bit.ly/node-security
Author of Security Headers 👉 bit.ly/http-security

Interests:
#OpenSource #NodeJS #AppSec #JavaScript #Containers #Docker #SupplyChainSecurity #Snyk #OWASP #GitHub #DevSecOps #DevRel #CNCF #OpenSSF #OpenJSF

0 Followers
0 Following
50 Posts
Joined November 04, 2022
Website:
https://lirantal.com
GitHub:
https://github.com/lirantal
Twitter:
https://twitter.com/liran_tal
Node.js Secure Coding:
https://www.nodejs-security.com/
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
If you're not concerned of malicious and insecure SKILL md files you should be and maybe I'll convince you in this presentation of mine form AI DevCon: https://www.youtube.com/watch?v=oJGX8GYLWxg&list=PLISstAySqk7KtlYPFps1ZnK9xNIMSVkDD&index=37 In this session you'll watch live hacking of a malicious skill and how it fools a coding agent for rogue actions, a prompt injection leaks your secrets over email, and a leaky skill passes credit card numbers straight through the LLM context. Then we flip to defense.
1
1
2
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2w ago
it feels weird but also right at the same time what is happening
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
what AX means
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
The OpenJS Foundation contributors leaderboard 🎉 Thank you to all of the amazing humans, some of whom are on this list that I am grateful to call friends, for building a better open-source world for us ❤️
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
let's talk about this planning skill (and in general), when they rely on pre-determined plan filenames then that mandates using worktrees, otherwise, other sessions will share the same plan files and you can't multi-task... what's your way of working for planning with agents?
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 1w ago
snapshot from the Snyk VulnBench when I set out to build the benchmarking harness so if I were to build a new benchmark - what questions would you want it to answer... ?
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
Boxdown vs NVIDIA OpenShell assessment for the base Docker image setup
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
it's 2026 and Atlassian didn't add export to Markdown in Confluence :(
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
working with a second brain is underrated if you're not yet there, you should commit to this now
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
you're all rushing into Skynet speculations from Mythos and other cybersecurity models but in the meanwhile, in the reality of things, about 3 years later after I disclosed these set of (CVE) vulnerabilities, I received a note that a maintainer will look into addressing them in a fork 🤷‍♂️
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
if you haven't yet jumped on the LifeOS wagon, well... there's no better time. go build yourself a second brain.
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
looks like a lot of you are working with agents in a highly privileged mode + highly sensitive environment (your local dev machine) how do you sleep at nights? 😅
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
Snyk VulnBench JS 1.0 shows that the best-scoring LLM configuration reached 75.4% Snyk-reference F1, leaving a 24.6-point gap against deterministic SAST reference reproduction. Go read up on this coding agents security benchmark
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
the pressure is real 😬
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
how long until we stop saying "AI agent" and just say "agent" ? I call 2 months
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
secure software factory >> software factory
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
A few weeks back we announced VulnBench at Snyk. It's a forward research benchmark project that I lead to uncover LLM security findings The benchmark isn't about a competition between AI-based scanning to SAST-based scanning, but rather centers on the differences and risks of both
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
you know why, right?
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2w ago
what if I ran /grill-me but I'd have the agent answer its own questions
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 1w ago
another finding from a seed/starter Python (Flaks) project which devs have likely built their projects with and had "adopted" the insecure code that leads to a security vulnerability (harmful IDOR here)...
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 1w ago
trustworthiness is engineered, and it's engineered where Snyk operates (context, tooling, guardrails) thanks for coming to my ted talk
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 1mo ago
jack of all trades, orchestrator top gun
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 1mo ago
When Claude Code prints that token stat (10k tokens) I assume those are output tokens, right? how do you know?
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 4w ago
wip for running the benchmarks on VulnBench 2.0 which is a new set of fixture data, larger apps codebase, varied language ecosystem... pretty interesting how harness + model are very much a pair, for example Codex Security agent with Terra on xhigh just isn't scoring high enough
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 1w ago
here's an example in action of coding agents suggesting whatever random open souce package that made sense, but... is it actually healthy? maintainable? free of vulnerabilities? who knows unless you install the Snyk MCP server and then you know (there's a package health tool)
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
it's been cooking for quite some time but it's not the duration but rather that it's a relatively small scope so now I'm super curious at what the agent stumbled onto throughout that required this amount of work to be invested... how do you all do agents observability locally?
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 1w ago
Claude Code + Snyk MCP Server = secure code at inception ✨ Video courtesy of the brilliant Brian Clark
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
Can I trick Gemini CLI to pop the calc? apparently yes: https://lirantal.com/blog/gemini-cli-invisible-unicode-skill-injection I disclosed a Gemini CLI prompt injection where invisible Unicode tag characters in SKILL md caused the agent to run a hidden command. Google closed the report as out of scope because the workspace was trusted and YOLO mode was enabled.
lirantal.com
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
vanity metrics of the day
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
Black Hat 2026 will be riddled with AI Security announcements but this one from Snyk I am genuinely excited about Agentic Development Security is how we started with shaping GenAI code to ensure secure and trusted output and then continued to MCP security and then Skill scanning
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
color me surprised 😅 ladies and gents, always push back
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
Do you want to join my colleague Vandana who received her 𝗔𝗜 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿 𝗙𝗼𝘂𝗻𝗱𝗮𝘁𝗶𝗼𝗻𝘀 certificate? Here's everything you'll learn as the baseline for AI security engineering: ✅ OWASP Top 10 for LLM Applications ✅ Addressing Shadow AI ✅ AI Threat Modeling ✅ Securing Agent Skills and MCP ✅ Securing Vibe Coding ✅ AI Red Teaming We created the curriculum, you should go take the training (on-demand)!
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
from CLI to an isolated workspace environment I can work with Claude Code app in under a minute. Slick DX powered by Boxdown ✨
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
Quick tip - in the latest update of Claude Cowork you can now select text on a doc (the opened right sidebar view) and then tell Claude what to change on it specifically
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 1mo ago
we're in 2026, AI-pilled and the right-click spelling menu in macOS is horrible and useless, what the actual hell
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 1w ago
Claude and me
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
this is what going agentic looks like, hockey stick all the way up ;-)
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
if you like this tshirt then shout out to Chris Suen who coined the trademark in a rando Slack conversation hit us up at Snyk and I'll show you what this means! ;-)
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
DevRel friends you should invest more in doing deep research I ran the VulnBench benchmark project at Snyk, which now graduated to a full-time Forward Research initiative under DevRel, and it's not only satisfying from a technical perspective but also incredibly energising to dive into the details
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
guess what really unlocks agentic loops? verifiable software ;-) yep, you still need to write tests, have a deterministic CI setup, and... security controls
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2w ago
hmmm, didn't Anthropic folks say that this model switch in between session is no longer an issue or did I miss something? that's from the Claude Code app
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 1w ago
kinda feel bad I'm doing a software update while at the lounge's wifi
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
would be nice to have the ChatGPT app support keyboard mappings for model definitions (model + reasoning + speed) so I can easily toggle between them you know ;-)
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
in case you were living under a rock and missed the OpenAI + Hugging Face incident from last week... Here, I highlighted everything you need to know from the incident report. Maybe emergent properties? Maybe Skynet early days. Maybe a nice PR. Either way, stay vigilant.
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
oh my god, new hell discovered
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 1w ago
if you think engineering and technical savy is unimportant beacuse you can just ask the agent... well, here's yet another example of pushing back and steering agents away from disaster and disappointed users
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
New npq feature 🎉 To help you with figuring out an alternative npm package when the latest one doesn't fit the security criteria, npq will not check prior versions published and suggest them instead Thank you to Brian Clark who suggested this improvement npm install -g npq@latest to get it
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
hah, I do appreciate this update from dependabot but like 10 years too late Snyk dependency upgrade introduced a 21 days cooldown period since 2020 in my repos I have this defaulting to 30 days. call me paranoid. I know.
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
appreciate the shoutout from Yigitcan Kaya on the Real World AI Security conference stage from a couple of weeks back on Snyk's ToxicSkills research malicious skills research is incredibly relevant and I'm grateful to have had the privilege to work alongside smart humans at Snyk who pioneered this work around agent skill security
0
0
0
0
Open post
Liran Tal :verified: @lirantal@infosec.exchange
· 2mo ago
I was really hoping to use VS Code for managing the second brain Obsidian-like vault but the extensions and overall capabilities are just terrible What did you all do? Just use Obsidian?
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 13:52:15 UTC