Leanpub Header

Skip to main content

The Agentic Security Playbook

Securing AI Coding Agents and the Software They Ship

The Agentic Security Playbook
Your agent just read a file you didn't think mattered, followed an instruction hidden in a web page, and pushed a commit. None of it looked suspicious. That's the shape of agentic security — and *The Agentic Security Playbook* is how you close the gap before someone else finds it.

Minimum price

$9.00

$19.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
About

About

About the Book

The Agentic Security Playbook: Securing AI Coding Agents and the Software They Ship

AI coding agents are no longer autocomplete. They read your files, hold credentials, call tools, fetch the web, and write code that ships to production. That makes them an extraordinarily productive teammate — and a brand-new attack surface.

This is the playbook for securing both.

  • secure the agent itself. Prompt injection turns untrusted content into instructions. Secrets sit one bad read away from exfiltration. MCP servers expand the supply chain. And autonomy means the agent acts faster than you can review. You'll learn to contain all of it with least privilege, approval gates, sandboxing, and scoped identities.
  • You'll secure the code it produces.** AI-generated code is plausible — and plausibly vulnerable. You'll learn its characteristic flaws, run a systematic security review, treat model output as untrusted, and catch the supply-chain traps (including hallucinated dependencies) before they ship.
  • You'll operate it like a security program.** Replayable audit trails, guardrails as code, a compliance crosswalk (OWASP LLM/Agentic Top 10, NIST AI RMF, SOC 2, ISO 42001, EU AI Act), and incident runbooks for the failures unique to agents.

Inside you'll find:

  • The two-front model that organizes everything: secure the agent, secure the output
  • A working agent threat model, with a reusable one-page template
  • The prompt-injection defense stack and a test harness you can run
  • Permission, sandbox, and policy recipes (with real config snippets)
  • MCP and tool supply-chain vetting checklists
  • A vulnerability field guide with symptom → fix → test for each class
  • Red-team exercises and purple-team detection pairings
  • Agent incident-response runbooks and tabletop drills
  • A capstone that hardens a real agent workflow end-to-end
  • A compliance control map so you can answer the CISO's questions

Written for developers, platform engineers, and security teams who want to move fast with AI agents — **without becoming the breach story.** Because the agent may be the one acting, but the responsibility is still yours.


Companion to Vibe Coding with OpenCode: From Beginner to Pro. Examples run on OpenCode (free and open source), and every principle transfers to any agent.

Author

About the Author

Kristian Reformis

Kristian Reformis is a dedicated IT educator and tech enthusiast with a mission to bridge the gap between complex technology and modern pedagogy. With years of experience in the classroom, he has seen firsthand the challenges teachers face in an increasingly digital world.

Known as "The Reformist Teacher," Kristian specializes in making advanced IT concepts—from coding to Artificial Intelligence—accessible and actionable for educators of all backgrounds. He believes that technology should not be a burden to teachers, but a powerful catalyst that allows them to focus on what truly matters: inspiring the next generation.

When he isn’t exploring the latest AI tools or developing digital solutions for schools, Kristian enjoys sharing his insights on educational reform and the future of work. The AI-Driven Educator is his latest contribution to empowering teachers worldwide to reclaim their time and transform their classrooms.

Contents

Table of Contents

Chapter 1: The Agentic Threat Shift

  1. 1.1 From Tools to Actors: What Actually Changed
  2. 1.2 The Two Fronts: Securing the Agent and the Code It Ships
  3. 1.3 Why Traditional AppSec Misses Agents
  4. 1.4 Blast Radius, Autonomy, and Speed: The New Risk Math
  5. 1.5 The Governing Principle: Least Privilege, Human-Gated
  6. 1.6 How to Use This Playbook
  7. 1.7 Chapter Summary
  8. 1.8 Exercises
  9. 1.9 What’s Next

Chapter 2: How AI Agents Actually Execute

  1. 2.1 The Agent Loop: Read, Decide, Act, Observe
  2. 2.2 Capabilities Are Tools: Shell, Files, Network, MCP
  3. 2.3 Permissions, Approvals, and Modes
  4. 2.4 Context: The Real Attack Surface
  5. 2.5 Where the Trust Boundaries Actually Lie
  6. 2.6 An Annotated Execution Trace
  7. 2.7 Chapter Summary
  8. 2.8 Exercises
  9. 2.9 What’s Next

Chapter 3: Threat Modeling Agents

  1. 3.1 Assets, Actors, and Trust Boundaries
  2. 3.2 A Taxonomy of Agent Threats
  3. 3.3 STRIDE for Agents
  4. 3.4 Data-Flow Diagrams for Agent Systems
  5. 3.5 Ranking: Likelihood × Impact × Blast Radius
  6. 3.6 Deliverable: A One-Page Agent Threat Model
  7. 3.7 Chapter Summary
  8. 3.8 Exercises
  9. 3.9 What’s Next

Chapter 4: Secrets and the Context Trap

  1. 4.1 Everything in Context Is Exfiltrable
  2. 4.2 Secret Sprawl: Repos, Prompts, Sessions, Traces
  3. 4.3 Keeping Secrets Out: Ignore, Scope, Scan
  4. 4.4 Runtime Injection: Env, Vaults, Short-Lived Tokens
  5. 4.5 The Leak Playbook: Revoke → Rotate → Audit → Encode
  6. 4.6 Prevention as Code: Pre-Commit and Agent Hooks
  7. 4.7 Chapter Summary
  8. 4.8 Exercises
  9. 4.9 What’s Next

Chapter 5: Prompt Injection and Untrusted Content

  1. 5.1 The Mechanism: Data vs. Instructions
  2. 5.2 Direct vs. Indirect Injection
  3. 5.3 The Sources: Web, Repos, Issues, MCP Output, Files, Memory
  4. 5.4 Defense in Depth: Framing, Delimiters, Canaries
  5. 5.5 Containment: Permissions Limit What Injection Can Do
  6. 5.6 Tool Poisoning and Cross-Tool Injection
  7. 5.7 Building an Injection Test Harness
  8. 5.8 When Injection Succeeds: Response
  9. 5.9 Chapter Summary
  10. 5.10 Exercises
  11. 5.11 What’s Next

Chapter 6: Permissions, Approvals, and Least Privilege

  1. 6.1 The Permission Model as a Security Control
  2. 6.2 Least Privilege for Tools
  3. 6.3 Approval Gates: Where Humans Must Stand
  4. 6.4 Deny-by-Default and Allowlists
  5. 6.5 High-Risk Action Classes
  6. 6.6 Designing a Permission Policy
  7. 6.7 Anti-Patterns: Auto-Approve Everything
  8. 6.8 Chapter Summary
  9. 6.9 Exercises
  10. 6.10 What’s Next

Chapter 7: Isolation and Sandboxing

  1. 7.1 Why Prompts Are Not a Security Boundary
  2. 7.2 Sandbox Levels: Process, Container, VM, MicroVM
  3. 7.3 Filesystem Scoping and Read-Only Mounts
  4. 7.4 Network Egress Control
  5. 7.5 Resource Limits and Blast-Radius Caps
  6. 7.6 Ephemeral Mandates: A Fresh Container per Task
  7. 7.7 Run the Agent with Zero Credentials It Doesn’t Need
  8. 7.8 Chapter Summary
  9. 7.9 Exercises
  10. 7.10 What’s Next

Chapter 8: MCP and Tool Supply-Chain Security

  1. 8.1 MCP Expands the Attack Surface
  2. 8.2 Threat Classes: Malicious Servers, Tool Poisoning, Rug Pulls
  3. 8.3 Vetting an MCP Server
  4. 8.4 Authentication and Scoped Credentials for Servers
  5. 8.5 Gateways and Registries: Centralizing Trust
  6. 8.6 Pinning, Versioning, and Integrity
  7. 8.7 A Secure MCP Adoption Checklist
  8. 8.8 Chapter Summary
  9. 8.9 Exercises
  10. 8.10 What’s Next

Chapter 9: Agent Identity and Credentials

  1. 9.1 Agents Need Identities, Not Your Credentials
  2. 9.2 Short-Lived, Scoped, Auditable Tokens
  3. 9.3 Service Accounts and Delegated Access
  4. 9.4 Scoping Cloud and API Permissions
  5. 9.5 The Privilege-Escalation Traps
  6. 9.6 Rotation for Long-Lived Agents
  7. 9.7 Chapter Summary
  8. 9.8 Exercises
  9. 9.9 What’s Next

Chapter 10: Reviewing AI-Generated Code for Exploitable Flaws

  1. 10.1 Why AI Code Has Characteristic Flaws
  2. 10.2 The Systematic Security-Review Prompt
  3. 10.3 Priority Order: Auth, Money, Input, PII, Crypto
  4. 10.4 Evidence-Backed “No Issues Found”
  5. 10.5 AI Assists; the Human Decides Severity
  6. 10.6 Wiring Review Into the Workflow
  7. 10.7 Chapter Summary
  8. 10.8 Exercises
  9. 10.9 What’s Next

Chapter 11: The Vulnerability Classes That Bite

  1. 11.1 Injection (SQL, Command, Template, LLM Output Handling)
  2. 11.2 Broken Authorization — The #1 Finding
  3. 11.3 Secrets Committed in Code
  4. 11.4 Insecure Defaults and Weak Crypto
  5. 11.5 Unsafe Deserialization, SSRF, Path Traversal
  6. 11.6 Treating Model Output as Untrusted (OWASP LLM05)
  7. 11.7 Excessive Agency in Generated Systems (OWASP LLM06)
  8. 11.8 A Field Guide: Symptom → Fix → Test
  9. 11.9 Chapter Summary
  10. 11.10 Exercises
  11. 11.11 What’s Next

Chapter 12: Supply Chain and Dependency Risk

  1. 12.1 The Hallucinated-Dependency Problem (Slopsquatting)
  2. 12.2 A Dependency Verification Workflow
  3. 12.3 Lockfiles, Pinning, and Reproducibility
  4. 12.4 SBOMs and Continuous Scanning
  5. 12.5 Build and CI/CD Supply Chain
  6. 12.6 License and Provenance
  7. 12.7 Chapter Summary
  8. 12.8 Exercises
  9. 12.9 What’s Next

Chapter 13: Security Testing and Red-Teaming with Agents

  1. 13.1 Turning the Agent on Itself
  2. 13.2 Generating Security Tests and Abuse Cases
  3. 13.3 Fuzzing and Property-Based Testing
  4. 13.4 An Automated Red-Team Prompt Harness
  5. 13.5 Adversarial Couplets: Builder and Breaker
  6. 13.6 Measuring Security Coverage
  7. 13.7 Chapter Summary
  8. 13.8 Exercises
  9. 13.9 What’s Next

Chapter 14: Privacy, Confidentiality, and IP

  1. 14.1 Where Your Code and Data Actually Go
  2. 14.2 Provider Data Policies: Training, Retention, Residency
  3. 14.3 Keeping Sensitive Work Local
  4. 14.4 PII and Regulated Workloads
  5. 14.5 Confidentiality Across Multi-Agent and Third-Party Tools
  6. 14.6 IP, Licensing, and Attribution of AI-Generated Code
  7. 14.7 Chapter Summary
  8. 14.8 Exercises
  9. 14.9 What’s Next

Chapter 15: Observability, Audit, and Traces

  1. 15.1 What to Log (and What Never to Log)
  2. 15.2 Agent-Specific Trace Fields
  3. 15.3 Tamper-Evident Audit Trails
  4. 15.4 Detecting the Anomalous in Agent Activity
  5. 15.5 Retention, Access, and Privacy of Logs
  6. 15.6 Alerts That Matter
  7. 15.7 Chapter Summary
  8. 15.8 Exercises
  9. 15.9 What’s Next

Chapter 16: Policy, Governance, and Compliance

  1. 16.1 Governance for Agents: What’s Different
  2. 16.2 The Policy Inventory (What Rules Do You Actually Have?)
  3. 16.3 A Control Map: Threats → Controls → Evidence
  4. 16.4 Framework Alignment
  5. 16.5 Roles, Accountability, and the Human in the Loop
  6. 16.6 Keeping Policy Alive (Not Shelfware)
  7. 16.7 Chapter Summary
  8. 16.8 Exercises
  9. 16.9 What’s Next

Chapter 17: Incident Response for Agents

  1. 17.1 Why Agent Incidents Are Different
  2. 17.2 The Agent IR Playbook (Phases)
  3. 17.3 The Revoke-Rotate-Audit-Encode Toolkit
  4. 17.4 Hands-On: A Secret Exfiltrated via Injection
  5. 17.5 Forensics from Traces
  6. 17.6 Recovery and Hardening
  7. 17.7 Chapter Summary
  8. 17.8 Exercises
  9. 17.9 What’s Next

Chapter 18: Threat-Modeling and Red-Teaming Your Stack

  1. 18.1 From One-Off to Cadence
  2. 18.2 Modeling the Whole Stack (Not Just a Feature)
  3. 18.3 The Standing Threat Model Document
  4. 18.4 A Continuous Red-Team Cadence
  5. 18.5 Purple-Teaming: Close the Loop with Defenders
  6. 18.6 Metrics That Drive Improvement
  7. 18.7 Chapter Summary
  8. 18.8 Exercises
  9. 18.9 What’s Next

Chapter 19: The Secure Agent Platform

  1. 19.1 Principles of a Secure Platform
  2. 19.2 The Reference Architecture
  3. 19.3 The Secure Default Config
  4. 19.4 Identity, Secrets, and Egress
  5. 19.5 Tool / MCP Gateway
  6. 19.6 Verification & Guardrails Pipeline
  7. 19.7 Observability & Audit Backbone
  8. 19.8 A Maturity Model & Adoption Path
  9. 19.9 Chapter Summary
  10. 19.10 Exercises
  11. 19.11 What’s Next

Chapter 20: Capstone — Harden a Real Agent Workflow

  1. 20.1 Choose Your Workflow
  2. 20.2 Step 1: Model It
  3. 20.3 Step 2: Secure the Agent
  4. 20.4 Step 3: Secure the Output
  5. 20.5 Step 4: Observe, Govern, and Respond
  6. 20.6 Step 5: Red-Team and Prove It
  7. 20.7 The Before/After Scorecard
  8. 20.8 Chapter Summary
  9. 20.9 Exercises
  10. 20.10 What’s Next (The Book’s Closing)

Appendix A: Agent Hardening Checklist

  1. 1. Context & Secrets (Ch. 4)
  2. 2. Prompt Injection (Ch. 5)
  3. 3. Permissions & Approvals (Ch. 6)
  4. 4. Isolation & Sandboxing (Ch. 7)
  5. 5. Tools & MCP (Ch. 8)
  6. 6. Identity & Credentials (Ch. 9)
  7. 7. Output Review (Ch. 10–11)
  8. 8. Dependencies & Build (Ch. 12)
  9. 9. Testing & Red-Teaming (Ch. 13)
  10. 10. Data, Privacy & IP (Ch. 14)
  11. 11. Observability & Audit (Ch. 15)
  12. 12. Governance (Ch. 16)
  13. 13. Incident Response (Ch. 17)
  14. 14. Standing Practice (Ch. 18–20)

Appendix B: Prompt Injection Payload & Defense Library

  1. B.1 Payload Categories
  2. B.2 Test Harness (v1)
  3. B.3 Defense Layers (Defense in Depth)
  4. B.4 Quick Reference: Payload → Defense → Test
  5. B.5 Recording Results

Appendix C: Permission, Sandbox, and Policy Cookbook

  1. C.1 Permission Recipes
  2. C.2 Sandbox Recipes
  3. C.3 High-Risk Gate Recipes (Ch. 6)
  4. C.4 Brokered Credential Recipes (Ch. 9)
  5. C.5 Egress Allowlist Recipes (Ch. 7, 14, 17)
  6. C.6 Dependency & Build Policy Recipes (Ch. 12)
  7. C.7 Scheduling & Autonomy Recipes (Ch. 6, 16)
  8. C.8 Quick Picks

Appendix D: Secure Rules and AGENTS.md Templates

  1. D.1 Global Baseline (put in your platform repo)
  2. D.2 Project Variant — Web Application
  3. D.3 Project Variant — Infrastructure / Platform
  4. D.4 Project Variant — Regulated / Local-Only
  5. D.5 Per-Task Overlay (drop into a task/PR prompt)
  6. D.6 Rules for Specific Risky Patterns (snippets to mix in)
  7. D.7 Layering Model
  8. D.8 Quick Reference

Appendix E: MCP Security Reference

  1. E.1 Threat Model for MCP
  2. E.2 Vetting Checklist (before connecting any server)
  3. E.3 Trust Tiers
  4. E.4 Gateway & Config Recipes
  5. E.5 Reviewing Tool Descriptions (Indirect Injection)
  6. E.6 MCP Threat → Control → Test
  7. E.7 Quick Reference

Appendix F: Compliance Control Map

  1. F.1 Core Compliance Control Map
  2. F.2 Framework Cheat-Sheet (what each wants from you)
  3. F.3 Building Your Own Map
  4. F.4 Answering an Audit / Questionnaire
  5. F.5 Quick Reference

Appendix G: Glossary and Further Reading

  1. G.1 Glossary
  2. G.2 The Book’s Principles, in One List
  3. G.3 Further Reading
  4. G.4 Closing Note

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub