Talk All Audiences 16:50 - 17:20 August 08, 2026

saikishu

Helen Oakley

Your AI agent approved the vendor, sent the status email, processed the payment, and BCC'd customer PII to an attacker's dead drop. One turn, no jailbreak, no prompt injection of the user. The MCP tool metadata the agent trusted had been quietly rewritten upstream, and from the model's view it was just doing its job.

A live attack-to-defense demo on OWASP FinBot CTF, a deliberately vulnerable multi-agent platform (Juice Shop for agentic AI) with real MCP agents running onboarding, compliance, and payments.

Act I, Kill Chain: a poisoned tool description with security-framed exfil logic no model refuses. One admin request triggers vendor lookup, PII harvest, BCC exfil, and payment. Output stays clean.

Act II, Guardrail: poison stays. We deploy a ~40-line before_tool webhook that inspects invocations live. Benign calls pass, exfil dies on the wire.

Tool metadata sits inside the agent's trust boundary, and few pin or diff-review it. Clone the CTF and keep pwning.

saikishu

Chief Architect, Straiker | OWASP Contributor

Venkata Sai Kishore Modalavalasa is Chief Architect & Engineering Leader at Straiker, building AI security products for AI-native apps at scale. With 15+ years in cybersecurity and distributed systems, he scaled Cyberfend to acquisition by Akamai, where he led bot detection and web security engineering. He’s an OWASP author contributing to AI Exchange, AIBOM, Top 10 for Agentic Applications, OWASP GenAI Security Project, creator and co-lead of OWASP FinBot CTF, and holds multiple security patents.


Helen Oakley

Cybersecurity and AI visionary, shaping secure technological trends across the industry.

Helen Oakley, CISSP, GPCS, GSTRT, works at the intersection of AI, cybersecurity, and software supply chains—where the rules are still being written. At SAP, she leads a global team of architects, security experts, and scientists, securing development and pipelines at scale. Helen is part of the core leadership team of the OWASP GenAI Security Project and co-leads initiatives on AIBOM and Agentic Security, contributes into industry papers like Agentic AI Threats & Mitigations Guide, OWASP Top 10 for Agentic Apps, and more. Helen has co-led AIBOM efforts with CISA, and is the original creator of the OWASP FinBot CTF and the first open-source OWASP AIBOM Generator for Hugging Face models. Named one of the Top 20 Canadian Women in Cybersecurity, she co-founded LeadingCyberLadies.com to support the next wave of builders, breakers, and leaders.