We let an AI agent execute Bash and lived to talk about it — Sarah Sanders, PostHog
PostHog built Wizard, an AI tool that automates SDK installation and builds dashboards on developers' machines — approximately 8,000 users per week.
Sarah Sanders, a security engineer there, recognized that an AI system with command-line access is dangerous: an attack can originate from an insecure pull request that becomes part of the installation pipeline. Her audit found that even without obvious malice, two innocent functions together create gaps — attacks compose while code review does not. She built a detector based on YARA rules that reports suspicious patterns without acting itself, and layered an AI system on top that advises but never enforces.
Vibekollen prepared this summary with AI from the original publication. The content belongs to AI Engineer.