Skip to main content
Zach Korman

Zach Korman

CEO & Cofounder of Embroidery, building AI-driven threat detection for AI agents; previously CTO at Pistachio.

Jul 30, 2026

28:01
For the folks that are not in InfoSec, what would your advice be to them on how to be cautious about these projects that are being hoisted onto them, how to properly vet the tools and the security tools that they're using? What kind of advice would you give to non-security folks who are open-minded and want to hear what you have to say to help secure themselves better?
28:24
Yeah, so especially in terms of like if you're in an organization, because I think individuals are a bit of a different animal.
28:30
For an individual who's just trying to do AI stuff like at home, the best things you can do is limit third-party exposure.
28:37
So like you don't need to download every skill and you don't need 40 MCP servers.
28:44
Like every new piece of third-party content you add is just a risk, right? And so I think actually like if you approach it if you're like on your personal computer trying to play with like clod or whatever uh although you shouldn't because i don't like anthropic uh if you're playing with codex which i guess i'll have to defend because i don't like clod um then basically you will be best off by just ensuring you don't have doubt you don't download skills from you know mpx skills ad you actually if you need one you can copy paste it and better yet write your own uh even better i I only have three skills that are written by me.
29:24
I've never used more than that because they also pollute context.
29:28
MCP servers, I literally, I've only ever used, I think I've won at any given moment because I don't have any great need.

5 MINS LATER

34:35
yourself.
40:02
What sort of settings should folks be looking for or aware of to adjust on these things?
40:09
Yeah, I'll be honest, my take on this is most the developers are gonna set, and most people in your organization are gonna set everything to as YOLO mode as they possibly can.
40:23
And insofar as you don't allow them to, they will just not use it.
40:26
So like I've seen a lot of security advice around like don't let people run dangerously skip permissions or which is basically the let it run on its own permission.
40:38
Being honest, people are gonna run that permission and if you don't let them then they're gonna run their own Claude code and they're gonna do it themselves.
40:46
I think that the settings, he has a good point about sharing settings.
40:52
So there are some settings around like, you know, not allowing people to click share because that makes things public.

6 MINS LATER

46:59
So that's really all you got when you're doing business with other organizations is the contract

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.