Liran Tal
banner
lirantal.com
Liran Tal
@lirantal.com
🦄 Node.js Secure Coding: http://nodejs-security.com

🌟 @GitHub Star
🏅 @OpenJS Pathfinder award for Security
🥑 DevRel at @snyksec
To everyone who attended my talk today at #AGNTCon + #MCPCon Europe in Amsterdam (yay, windmills!) - I uploaded my deck as a PDF to the session on sched, so you're welcome to browse through and re-visit the topics

Should be freely available to everyone else too:
September 18, 2026 at 6:00 PM
wrote a book on this 2 years ago
maybe you want to read
or give it to your agent
September 17, 2026 at 6:01 PM
lol, if only it was that easy, right
or... maybe it is? 😯
ask me :)
September 17, 2026 at 3:01 PM
I like how Ezra points out generation step vulnerabilities vs prevention altogether. Recommended read: snyk.io/blog/is-prev...
September 17, 2026 at 9:01 AM
reminder to use the boxdown CLI to configure your ChatGPT Codex or Claude Code to use local isolated container environments for agentic work (magically sets everythig up for ya!)

yes, it's open source 🎉

p.s. Cursor is supported too if you're a fan of it
September 17, 2026 at 6:00 AM
Snyk VulnBench headline numbers

How well do other models compare with an F1 agreement score with Snyk Code security findings from a SAST scan and their error rate (Opus 4.7 Max was surprising!)
September 16, 2026 at 6:00 PM
geeky but the terminal is back and I was having fun building up the Snyk VulnBench harness for benchmark purposes (now prefer the open source Harbor framework / CLI)

learned so much from building the harness though
totally recommend
September 16, 2026 at 3:00 PM
early back in May when I ran the Snyk VulnBench benchmark I compared various models to a Snyk F1 reference score (can they match what Snyk Code is reporting as security vulnerabilities)

here's what they reported
bonus: error bars
September 16, 2026 at 9:00 AM
Following is how anti-trojan-source CLI detects cases of potentially harmful characters, identified from the Glassworm attack:
September 16, 2026 at 6:00 AM
lol we truly are centering divs using AI 🤣
September 15, 2026 at 6:00 PM
lol what

this is Sonnet 5 on Medium so yes fine not Astra or Fable but come'on

always always always verify and validate, I cannot stress this enough
September 15, 2026 at 3:01 PM
highly intelligent than Sol I guess
September 15, 2026 at 9:00 AM
if you haven't been working with an AI agent (whether Claude Cowork or otherwise) as your main driver for a second brain at work you're falling behind
September 15, 2026 at 6:00 AM
what hell is this
apple losing more of the dev ex
September 14, 2026 at 6:00 PM
autoapprove is cool but doing it without a malicious package slipping in is cooler 😉
September 14, 2026 at 3:00 PM
wip for running the benchmarks on VulnBench 2.0 which is a new set of fixture data, larger apps codebase, varied language ecosystem...

pretty interesting how harness + model are very much a pair, for example Codex Security agent with Terra on xhigh just isn't scoring high enough
September 14, 2026 at 9:00 AM
wip for running the benchmarks on VulnBench 2.0 which is a new set of fixture data, larger apps codebase, varied language ecosystem...

pretty interesting how harness + model are very much a pair, for example Codex Security agent with Terra on xhigh just isn't scoring high enough
September 14, 2026 at 6:00 AM
We have been working on the OWASP MCP Security Taxonomy - an open, vendor-neutral framework designed to create a common language for MCP security risks, weaknesses, attack patterns, controls, detections, and test cases: github.com/OWASP/MCP-Ta...

Go check it out and give feedback
GitHub - OWASP/MCP-Taxonomy: OWASP MCP Taxonomy
OWASP MCP Taxonomy. Contribute to OWASP/MCP-Taxonomy development by creating an account on GitHub.
github.com
September 11, 2026 at 6:00 PM
doing the benchmark thing again
September 11, 2026 at 3:00 PM
do we have this chart with updated models?
would appreciate if someone has the prompt injection resistance from model cards handy to share
September 11, 2026 at 9:00 AM
this no longer works I think but how fun it is that you can just send text to trigger a denial of service in downstream AI agents?
September 11, 2026 at 6:00 AM
Snyk partnered with AI Engineer and other great companies and labs to put together the AI Security Summit in San Francisco on October 15th

I'll be there. Are you coming? Hit me up and check out the event: aisecuritysummit.com
September 10, 2026 at 6:00 PM
lol Tobi you're a genius
September 10, 2026 at 3:00 PM
lol should I be worried chat
September 10, 2026 at 9:00 AM
running the Codex Security agent harness through a code base and btw just its Threat Modeling scope of work exceeded $2 in cost for a typical Golang application using Sol on High reasoning mode
September 10, 2026 at 6:00 AM