TNS Agents: Tzvika Shneider, Founder and CEO, Pynt

The New StackAbout 7 min readAug 22, 2025Watch original
THE SUMMARYAI-generated

Key Concepts:

  • API Security
  • MCP (Multi-Context Protocol) Security
  • LLM (Large Language Model) Security
  • Application Security Testing (AST)
  • AI-assisted Security
  • Agentic Security
  • Prompt Injection
  • Contextual Security
  • Shift Left/Shift Right Security
  • Adversarial AI

1. Introduction and Guest Speaker:

  • The hosts, Alex and Frederick, introduce Sria Schneider, co-founder of Pint, located in Tel Aviv, Israel.
  • Sria expresses hope for peace and normalcy in the world, given the current geopolitical situation.
  • The startup scene in Israel is described as being at its peak, with a lot of activity in cyber security and AI.
  • Sria mentions that while 2021 saw companies raising multiple rounds of funding, the current trend is more companies raising a single round.
  • Pint is a US company with an Israeli subsidiary, and Sria spends a lot of time traveling to meet customers in the US, UK, and Israel.

2. Current Trends in Tech Coverage:

  • Frederick notes the rise of command-line agents like Cloud Code, Gemini CLI, and Kira from AWS.
  • He also mentions Code Interpreter from OpenAI as an interesting development.
  • Alex points out the unexpected departure of GitHub's CEO, Thomas Dohmke, and the increasing integration of GitHub into Microsoft.
  • Frederick mentions a research from LeadDev showing that Cursor was more popular than GitHub Copilot among developers.
  • The discussion revolves around the overwhelming number of developer tools available and the need to determine which ones are effective.

3. AI Tool Usage and Effectiveness:

  • Sria mentions that Pint uses some AI tools internally.
  • She notes that while CEOs and founders are pushing for faster development with AI tools, their effectiveness is still in a "brown field" stage.
  • Overuse of AI tools can waste time, while underuse doesn't provide enough benefit.
  • AI tools often lack the necessary context for specific tasks.
  • Sria compares the current state of AI coding tools to semi-autonomous cars, noting that they are not yet fully autonomous.
  • She illustrates this with the example of asking ChatGPT and Claude for a random number, which both returned the same result (47), indicating similar foundation models.

4. Security vs. Functionality in AI:

  • Sria quotes the CEO of Lemonade, who compared the AI revolution to the shift from horses to cars, where safety (security) was only considered after functionality was established.
  • She emphasizes that security always comes after functionality.
  • She believes that AI will drastically change the future, creating a larger gap between generations.

5. Pint's Evolution from API Security to MCP Security:

  • Sria explains that Pint has evolved from focusing solely on API security to encompassing all aspects of application security, including LLM APIs and MCP agents.
  • She clarifies that Pint didn't pivot but rather expanded its scope to cover the evolving landscape of application development.
  • She emphasizes that everything is ultimately a piece of code being compiled and built, and all layers (web, APIs, LLMs, MCPs) are part of the same application.
  • Pint aims to be a one-stop shop for automated application security testing, focusing on "hacking" applications early in the development process to identify and fix vulnerabilities.
  • She notes that most issues are now in data flows and business logic rather than the infrastructure.

6. MCP Security Implications:

  • Sria explains that APIs are deterministic, while MCPs are undeterministic and have their own reasoning.
  • Pint conducted research on 281 real-world MCPs and found that the risk increases significantly when multiple MCPs work together.
  • She provides an example of connecting Gmail and code execution MCPs to Claude, demonstrating how Claude could be manipulated to write phishing emails and execute code.
  • She emphasizes that MCPs introduce a new attack surface and don't replace existing security concerns like API security and prompt injection.

7. MCP Attack Scenarios and Mitigation:

  • Sria describes scenarios where malicious MCPs can be used to access sensitive data, such as passwords stored in the file system.
  • She notes that the main problem is still around API security, which is amplified by MCPs due to uncontrolled data sending between agents.
  • She observes that organizations are starting to develop MCP security plans, but none have mature plans yet.
  • She mentions the risk of malicious servers and the need for visibility into which MCPs are being used within an organization.
  • She notes that organizations are either adopting an open policy or blocking everything, with the latter often leading to users bypassing security measures.

8. Balancing Security and User Experience:

  • Sria acknowledges the challenge of balancing security with the need for innovation and user experience.
  • She notes that engineers have a strong voice and prioritize faster innovation.
  • She gives an example of how users can bypass consent prompts in AI tools by selecting "never ask me again," which can create security risks.
  • She distinguishes between IT security (securing internal tools) and application security (securing the applications that a company develops and sells).

9. Autonomy vs. Security in AI Agents:

  • Sria agrees that a security-first approach can limit the autonomous capabilities of AI agents.
  • She draws an analogy to the evolution of autonomous vehicles, noting that they are not yet fully autonomous and rely on guardrails and extensive data.
  • She believes that AI will eventually become super-agentic, but it will require implementing guardrails and safer models.
  • She mentions Google's agent-to-agent protocol (A2A) but notes that customers are still focused on basic API security issues.

10. The Future of AI and Security:

  • Sria emphasizes that AI is not new and cites her experience with automotive cyber security in 2015-2016.
  • She notes that tasks that used to take months can now be done in minutes with AI.
  • She believes that AI will become an infrastructure like electricity, but regulations may delay its adoption in certain industries.
  • She acknowledges that adversaries will also use AI to build their tools, creating a race between attackers and defenders.
  • Pint plays the adversarial role to understand and automate adversarial thinking.
  • She warns that AI can be used for unethical purposes, such as deepfakes.
  • She emphasizes the need to put the right guardrails in place and acknowledges that everything is ultimately hackable.

11. Pint's Approach to Security:

  • Pint's goal is to help customers release secure software that is difficult to hack.
  • They focus on discovering assets, attacking them to identify vulnerabilities, and helping organizations fix the issues.
  • Pint's approach is AI-assisted rather than fully agentic, and they carefully choose where to implement AI to maximize value.
  • Sria emphasizes the importance of context in security testing, noting that Pint was one of the first vendors to offer contextual API security testing.
  • AI helps Pint understand the context of traffic and describe issues with business context.
  • She agrees that code analysis is less effective without context and that many issues arise from business logic and data flows.

12. Conclusion:

  • The hosts thank Sria for her insights.
  • Sria concludes by emphasizing that MCPs are evolving to be the new APIs but are not replacing them.
  • She reiterates that everything is application security, starting from code and involving business and data flows.
  • The next live stream will be from the Open Source Summit in Amsterdam.

Main Takeaways/Synthesis:

The discussion highlights the rapid evolution of application security in the age of AI, particularly with the emergence of MCPs and LLMs. While AI offers significant opportunities for improving security, it also introduces new attack surfaces and challenges, such as the need to balance autonomy with security and the risk of malicious AI agents. Pint's approach is to provide AI-assisted security testing that focuses on context and helps organizations release secure software. The key is to understand the evolving threat landscape and implement appropriate guardrails to mitigate risks while still enabling innovation. The future of security will likely involve a continuous race between attackers and defenders, with AI playing a central role on both sides.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.