Inga Cherny
Your coding agent ran 200 tool calls last night. File reads, shell commands, network requests, all with your permissions, mostly invisible. Today's defenses miss the attacks landing now: MCP tool poisoning, prompt injection via repo content, and credential-exfiltration chains where only the sequence is malicious.
I’ll present AgentsLeak, an open-source runtime monitor that hooks Claude Code and Cursor at the tool-call boundary and blocks before execution. Live demo: session telemetry showing the calls the agent made versus the calls it disclosed, and behavioral chain detection catching multi-step exfiltration.
Inga Cherny
ML Researcher at CrowdStrike
Inga Cherny is an ML Researcher at CrowdStrike specializing in AI security, LLM vulnerabilities, adversarial ML, and prompt injection defenses.
Previously, she was a security researcher at Cato Networks and a member of Cato CTRL, focusing on emerging threats, offensive and defensive security research.
With a decade of experience spanning security and applied machine learning, Inga focuses on uncovering new attack vectors and building more resilient AI and security systems.