- A coding agent on a laptop sits near private data, reads outside content and can reach the internet, which Michael Patterson called unacceptable in a secure enterprise.
- His fix is to run agents in isolated remote environments with limited reach, though he works for a company that sells exactly that.
Michael Patterson, a staff solutions engineer at Coder, spoke on the AI Engineer show. He argued that a coding agent on a developer's laptop meets three risky conditions at once. His answer is about placement: run agents somewhere other than the laptop.
What was said
Patterson described three threat layers. First, the laptop holds private data: personal files, credentials, company IP and databases. Second, the agent can pull in material from the internet, and nobody oversees what it fetches. Third, it can send data out. He called having all three on one machine basically not acceptable in a secure enterprise.
His main mechanism was prompt injection. That means hiding malicious instructions in material an agent trusts, such as error messages, support tickets or CI/CD logs, the automated records of software builds. The agent treats them as truth and may act on them.
He added that agents usually get broad access because they need it to work. A poisoned input can then push them to drop a table, upload files or post things they should not.
His fix is a remote, isolated environment. There the agent reaches only approved domains and touches only the credentials and data placed inside. Without it, he said, "It's not if, it's when you're going to have some kind of security incident by having an agent on that laptop."
Why it matters
Our reading: the first security choice is where an agent runs. A company can make that choice before it picks any tool. Patterson framed the weakness as an old one: handing software whatever access it asks for because it seems powerful. What changes is speed. In his words, "usually, agentic AI can do a lot of damage really fast."
For managers, that turns agent rollout into a question of limits. What data sits near the agent? What untrusted text does it read? Where can it send things? Patterson also said someone will be accountable when an agent does something unexpected. The owner should be named before the rollout, not after.
The other side
Patterson works for Coder, and he said cloud development environments are what Coder does. His recommendation matches his employer's product, so readers should weigh it with that in mind. His "not if, but when" is a judgment. The excerpts give no incident rates to back it.
Remote machines also do not remove every risk. He noted that an agent set up on a fresh box may pull code from a registry, a public package store, that could be contaminated. He also said agent security is no different from sound security practice for anyone. Isolation is one way to apply that practice, not the only one.
Written by the WebPulse Newsroom with AI assistance, and checked by our editorial review: every quotation was verified against the recording's transcript. How we use AI.
The conversation this talking point comes from
- AI Engineer: The Lethal Trifecta Is Already on Your Laptops — Michael Patterson, Coder (2026-10-10)





