Session Canvas
dev@sessioncanvas.local
Proposed by Marcus Lindgren · Ironvale
A threat model for agent tooling, with concrete isolation techniques and a live demonstration of three ways the naive design leaks credentials.
Marcus does application security for AI systems: untrusted tool calls, sandbox escapes, and the prompt injection you have not thought of yet.
Too close to a product pitch for this track, and the outline has no specifics.
Overlaps with two other proposals in this track. Good talk, question is whether we need all three.