Sep 2026
31 Mon
1 Tue
2 Wed
3 Thu
4 Fri
5 Sat 10:30 AM – 01:00 PM IST
6 Sun
Sep 2026
31 Mon
1 Tue
2 Wed
3 Thu
4 Fri
5 Sat 10:30 AM – 01:00 PM IST
6 Sun
Karan Bansal
Submitted Aug 20, 2026
Teams are putting AI coding agents into production workflows faster than they are putting controls around them. An agent that writes code also runs shell commands, reads secrets, installs packages, and pushes to git, at machine speed. This talk is about the control layer that has held up in production: event-driven hooks that intercept every tool call and allow, deny, or escalate it before execution.
What I’ll cover, all hands-on:
Toolkit: https://github.com/karanb192/claude-code-hooks (MIT, 481 stars, 1,584 tests). Earlier versions of this talk ran at the OWASP GenAI & Agentic Security Virtual Summit (May 2026) and CodeSecCon by SecurityWeek (Aug 2026); both recordings are public. This version leans into the production-honesty angle for The Fifth Elephant.
30-min talk plus 10 min Q&A, per the CFP format. Demos run offline.
Karan Bansal is Head of AI at ArmorCode, with over 10 years in security. He previously led security and privacy at Urban Company and was a founding engineer at AvidSecure, acquired by Sophos in 2019. He authored “Claude Code’s Most Underrated Feature: Hooks” and maintains the open-source claude-code-hooks toolkit (481 stars), a collection of security hooks for AI coding agents mapped to the OWASP LLM Top 10. He also built reddit-mcp-buddy (799 stars) and curates awesome-claude-skills (492 stars). He spoke on this topic at the OWASP GenAI & Agentic Security Summit and CodeSecCon by SecurityWeek in 2026, and contributes to SGLang and vLLM.
Sep 2026
31 Mon
1 Tue
2 Wed
3 Thu
4 Fri
5 Sat 10:30 AM – 01:00 PM IST
6 Sun
Hosted by
{{ gettext('Login to leave a comment') }}
{{ gettext('Post a comment…') }}{{ errorMsg }}
{{ gettext('No comments posted yet') }}