Talk
Your AI Agent Has Too Many Permissions: Building Secure Gemini Agents Beyond the Prompt
Everyone is talking about prompt engineering. Far fewer are talking about permissions. As AI agents evolve from answering questions to calling APIs, executing tools, and automating workflows, the biggest security risk is often not the model, it's giving the model too much access. In this live, demo-driven session, we'll build a Gemini-powered AI agent using Google AI Studio and the Agent Development Kit (ADK). Then we'll intentionally break it by exploiting excessive tool permissions, prompt injection, and unsafe automation flows. Finally, we'll redesign the agent using secure architectural patterns including least-privilege tool access, approval gates, structured outputs, and auditable actions.




