Your best developer just posted about shipping an incredible amount of code with an AI agent — and a day later, that same workflow deleted a production database. This is not a hypothetical tale. Michael Patterson, a staff solutions engineer at development-environment company Coder, recounted the anecdote while speaking on the AI Engineer podcast, and he argues it is the inevitable endpoint of a risk condition that already exists on the laptops of most enterprise developers today.
The culprit is what Patterson terms the “lethal trifecta” — a phrase he attributes to security researcher Simon Willison. It describes three properties of an agentic AI tool, each of which is individually tolerable but jointly fatal. The first is an agent sitting on a machine with access to private data: personal files, credentials, intellectual property, databases. The second is the agent’s ability to communicate outbound to the internet — meaning it can exfiltrate whatever it can read. The third is the ability to ingest content from the internet, meaning it can be fed malicious instructions.
Patterson’s rule of thumb is blunt. “One of these three isn’t really a big problem. But two out of three is completely unacceptable in any kind of secure enterprise environment.” Have all three, and it is not a question of whether a breach will occur, but when.
The attack surface is ordinary, not exotic
The threat is not a rogue superintelligence but a coding agent — Claude Code, Codex, OpenClaw — running on a developer’s laptop and given generous permissions precisely because, as Patterson puts it, “it needs access to do the work.” That broad access violates the least-privilege principle and turns a successful injection into an escalation.
Patterson identifies three attack patterns that exploit this surface: prompt injection, where malicious guidance is embedded in a source the agent trusts, such as error messages, support tickets, or CI/CD logs; context poisoning, where bad information is planted in documentation or data the agent retrieves; and privilege escalation, where injection or poisoning causes the agent to exceed its intended permissions — dropping tables, uploading data, or making unauthorized requests.
| Attack Mechanism | How It Works | Example Sources |
|---|---|---|
| Prompt injection | Malicious guidance hidden in a source the agent trusts | Error messages, support tickets, CI/CD logs |
| Context poisoning | Bad information planted in retrieval sources | Documentation, datasets |
| Privilege escalation | Injection or poisoning pushes agent beyond permissions | Dropping tables, uploading customer data, exfiltrating IP |
The common thread is predictable: agents are trusted more than any human employee would be, because they are fast and charmingly capable. Patterson’s counterpoint is that speed does not confer judgment. “We think that because AI is so powerful, we can just give it whatever it needs, and it’s not going to make the same kind of mistakes,” he said. The evidence from the field, he suggests, says otherwise.
The fix is boring security hygiene, applied to a new actor
Patterson is explicit that agent security is not a new discipline. It is “really no different from sound security practices for anyone.” What distinguishes his proposal is not novelty but the insistence that organizations apply classic controls to a component many have mistakenly exempted.
He prescribes a three-pillar architecture. First, control data access by moving the agent off the laptop and into an isolated virtual environment. Second, restrict external communication so the agent can only reach approved domains, sitting behind a VPN, VPC, and firewall with alerting when it breaches the perimeter. Third, lock down content, contact, and access with tightly scoped credentials.
The concrete implementation involves three components working together.
Cloud development environments (CDEs). Instead of running the agent on a laptop, the developer connects via URL, RDP, or SSH into a remote environment blessed by security and platform teams. The agent can only touch code, credentials, and data deliberately placed there. Patterson notes a secondary benefit: CDEs eliminate dependency and runtime conflicts — his example is a project needing Python 2 on a machine running Python 3 — so the agent starts working immediately rather than downloading from registries that could be contaminated.
Model proxy. A gateway between the agent and the LLM provider that sniffs and logs all traffic, strips injections, and sanitizes sensitive data. Patterson’s example is credit card data accidentally pasted into a prompt, which the proxy strips before it reaches the provider.
Agent firewall. At the process level, the firewall inspects what the agent is executing and denies commands not pre-approved — whether that is gh repo delete or a destructive SQL statement.

The real problem: shadow AI, now scaling into ‘Ninja AI’
The deepest organizational risk Patterson identifies is not a technical vulnerability but a human workaround. Block agent adoption, and employees do not stop using agents — they route around policy. “Shadow AI is just unauthorized usage of AI on your laptops,” Patterson said. “It’s a real problem because once you get AI on your laptop, you’re using your personal subscription, the enterprise doesn’t know what’s happening.”
The enterprise sees the damage only after the fact: databases dropped, personal information deleted, customer data uploaded, company IP extracted onto the public internet. And the problem is escalating. “We’re starting to see a new term in the industry called Ninja AI, which is shadow AI at scale,” he said. It is no longer one agent breaking a single pipeline; it is “multitudes of agents doing lots of things at an organization that no one knows until it’s too late.”
This dynamic creates a structural opportunity for vendors who sell sanctioned, governed environments rather than prohibition. Patterson’s framing — if a company blocks agents, employees buy personal Claude and ChatGPT subscriptions — explains why CISOs are now his most frequent conversation partners. He said he speaks with them once or twice a week.
The stakeholders each have a nameable fear
The rollout of agentic AI at a large company trips over three competing concerns, each attached to a specific role.
| Stakeholder | Primary Concern |
|---|---|
| CISO | Guardrails and boundaries; avoiding sole accountability for incidents |
| Platform admins / DevOps / security engineering | Observability — capturing every LLM call, alerting without alert fatigue |
| Developers | Technical debt, code bloat, security vulnerabilities, time spent fixing “AI slop” |
On the CISO side, Patterson frames the position sympathetically: they understand AI’s value and want people on the “development AI superhighway,” but they refuse to bless deployments without guardrails because when something goes wrong, the security team owns the blame. On developers, he notes an unresolved “holy war” — some of the most technical people remain unconvinced that AI writes code better than they do, and the accountability question hangs over every autonomous action. “At the end of the day, someone is going to be accountable when an agent actually does something that we didn’t expect it to do,” he said.
Alert fatigue gets its own warning. Once alerts become noise, the genuinely critical signals are missed — a familiar security pathology that takes on new stakes when agents operate at machine speed.
Coder is betting on on-prem, regulated buyers
Patterson’s employer is positioned squarely in the governance gap. Coder was founded in 2017 by three teenagers building Minecraft mods who were tired of configuring VMs to run the game. The company is now, in his words, an $80 million business. It builds remote development environments configured with Terraform, is open source, model-agnostic, and cloud-agnostic, and can be hosted on-prem. Patterson said Coder counts six of the top 10 US banks among its customers, along with hedge funds and several three-letter government agencies.
The buying criterion he states is simple: if a SaaS model does not work for you, if you have on-prem infrastructure, or if you cannot have code sitting on a developer laptop or outside a perimeter you control, Coder is usually a fit. That puts the company squarely in the path of the same forces driving separate corporate commentary this week — Zscaler’s CEO telling investors that “every CEO, every board is wanting to embrace AI, and what’s holding back is lack of security,” and Melius Research upgrading Microsoft on the thesis that enterprises are looking for the “adults in charge” of AI governance.
The unresolved tension in Patterson’s argument is that the controls he recommends add friction and cost, while the alternative he documents is employees routing around governance with personal subscriptions. The practical question for anyone evaluating this space is whether agent security consolidates into the development-environment platforms that already own the developer’s execution layer, or into standalone proxy and firewall vendors. Patterson is clearly betting on the former.
His closing guidance for enterprises is counterintuitive in an industry obsessed with velocity: slow down. “It’s okay to go slow so that you can think about your architecture, know what your infrastructure actually needs.” The agents are already on the laptops. The question is whether the guardrails arrive before the wake-up call.
Click Here For The Original Source.
