PocketOS wasn't a rogue AI story. It was keys left in the door

Jessie Grenfell
Jessie Grenfellโ€ข
PocketOS wasn't a rogue AI story. It was keys left in the door

The PocketOS incident has everyone clutching their pearls about rogue AI agents. An agent "found" a Railway API token with full production delete rights and used it. ๐Ÿ˜ฑ

Except this isn't an AI problem. It's the same problem that's been bankrupting companies via credential theft for decades. The only thing that changed is what picked up the keys that were left in the door.

This particular flavor of negligence has a long history:

๐Ÿ”‘ The 2020 Twitter hack? Social engineering to get employee credentials. Humans.

โ˜๏ธ The Capital One breach? A misconfigured cloud firewall. Humans.

๐Ÿชฃ Countless S3 buckets with customer data sitting publicly readable? Humans.

๐Ÿ” GitHub repos with hardcoded API keys committed by developers in a hurry? Also humans. (We've all seen it.)

The pattern is consistent: over-permissioned credentials, missing access controls, and zero principle of least privilege. Giving an agent delete rights on a production database is like handing a toddler scissors and blaming the toddler for what they destroy.

AI agents need the same security architecture discipline as always. Scoped credentials. Least privilege. Audit logging. Secrets management. None of this is new.

The "scary supergenius AI" narrative serves people who profit from the misconception that LLMs are genuinely intelligent rather than very fast, very convincing pattern matchers. The boring truth is that vibe-coded agentic solutions, built without security architecture experience, are just a faster way to make the same old mistakes.

At Codality, we build AI-powered operational solutions for complex, regulated industries where security architecture isn't optional and never has been. We know how to integrate agents into real workflows across financial services, insurance, and beyond without leaving the keys in the door.

Don't vibe code yourself out of business. Let's build the secure, scalable solution your business deserves together.

#AIEngineering #AgenticAI #LLMOps #CISO #CyberSecurity

Jessie Grenfell

Jessie Grenfell

Jessie has spent 20+ years architecting and delivering software for organizations where complexity is the norm โ€” financial services, insurance, nonprofits, and regulated industries where getting it wrong isn't an option. She specializes in the hard problems: unique operational workflows, cross-system integrations, and the kind of compliance requirements (HIPAA, CCPA, SOC 2) that most developers treat as someone else's job.

At Codality, she leads every principal engagement from discovery through delivery โ€” because she's seen what happens when that thread gets cut.