

Keycard Security Agent Workshop @ BLACK HAT
Your agents are reaching for real tools and real data. The risk isn't the capable agent, it's the standing secret it holds. One long-lived API key sitting in an agent's environment is one prompt injection or Shai-Hulud away from being read out.
At Black Hat Keycard is running a hands-on workshop where you build the answer on your own machine. We'll serve lunch and then you'll build a security agent that tracks and escalates security findings. By the end you'll run the agent without a .env and lock down everything it touches with Keycard, end to end.
What you'll learn:
Why standing secrets are the real risk in agentic systems, and how to build them so your server never holds one
How to give each tool exactly the access it needs, and nothing more
How to trace every hop of an agent delegation chain in a complete audit trail
How to set policy that blocks an over-permissioned action
Bring a laptop with Node and npm, a GitHub account, and your local coding agent (Claude Code, Cursor, Codex, or Copilot). Claude Code is preferred.
You'll walk out with a governed agent that you built, and a clear pattern for securing every agent you ship next. Join us if you're building MCP servers or agentic systems and want to learn how to control access to the resources your agent accesses.