Michael Patterson: The ‘Lethal Trifecta’ Already on Your Laptops Makes an AI Security Breach Inevitable — BigGo Finance #AI


Your best developer just posted about shipping an incredible amount of code with an AI agent — and a day later, that same workflow deleted a production database. This is not a hypothetical tale. Michael Patterson, a staff solutions engineer at development-environment company Coder, recounted the anecdote while speaking on the AI Engineer podcast, and he argues it is the inevitable endpoint of a risk condition that already exists on the laptops of most enterprise developers today.

The culprit is what Patterson terms the “lethal trifecta” — a phrase he attributes to security researcher Simon Willison. It describes three properties of an agentic AI tool, each of which is individually tolerable but jointly fatal. The first is an agent sitting on a machine with access to private data: personal files, credentials, intellectual property, databases. The second is the agent’s ability to communicate outbound to the internet — meaning it can exfiltrate whatever it can read. The third is the ability to ingest content from the internet, meaning it can be fed malicious instructions.

Patterson’s rule of thumb is blunt. “One of these three isn’t really a big problem. But two out of three is completely unacceptable in any kind of secure enterprise environment.” Have all three, and it is not a question of whether a breach will occur, but when.

The attack surface is ordinary, not exotic

The threat is not a rogue superintelligence but a coding agent — Claude Code, Codex, OpenClaw — running on a developer’s laptop and given generous permissions precisely because, as Patterson puts it, “it needs access to do the work.” That broad access violates the least-privilege principle and turns a successful injection into an escalation.

Patterson identifies three attack patterns that exploit this surface: prompt injection, where malicious guidance is embedded in a source the agent trusts, such as error messages, support tickets, or CI/CD logs; context poisoning, where bad information is planted in documentation or data the agent retrieves; and privilege escalation, where injection or poisoning causes the agent to exceed its intended permissions — dropping tables, uploading data, or making unauthorized requests.

Attack MechanismHow It WorksExample Sources
Prompt injectionMalicious guidance hidden in a source the agent trustsError messages, support tickets, CI/CD logs
Context poisoningBad information planted in retrieval sourcesDocumentation, datasets
Privilege escalationInjection or poisoning pushes agent beyond permissionsDropping tables, uploading customer data, exfiltrating IP

The common thread is predictable: agents are trusted more than any human employee would be, because they are fast and charmingly capable. Patterson’s counterpoint is that speed does not confer judgment. “We think that because AI is so powerful, we can just give it whatever it needs, and it’s not going to make the same kind of mistakes,” he said. The evidence from the field, he suggests, says otherwise.

The fix is boring security hygiene, applied to a new actor

Patterson is explicit that agent security is not a new discipline. It is “really no different from sound security practices for anyone.” What distinguishes his proposal is not novelty but the insistence that organizations apply classic controls to a component many have mistakenly exempted.

He prescribes a three-pillar architecture. First, control data access by moving the agent off the laptop and into an isolated virtual environment. Second, restrict external communication so the agent can only reach approved domains, sitting behind a VPN, VPC, and firewall with alerting when it breaches the perimeter. Third, lock down content, contact, and access with tightly scoped credentials.

The concrete implementation involves three components working together.