📕 Pwning and Defending AI Agent Code Interpreters 🤖

No ratings

Presented at BSides SF 2026 by

AI agents and chatbots increasingly run Python code interpreters, often for data analysis, that can be abused by attackers. We’ll show how prompt-to-RCE, credentials abuse, & C2 payloads work in these sandboxes, including a real AWS AgentCore breakout & hardening against code interpreter exploits.