
Claude Code Is INSANE, But Is It Safe? - #299
Show notes
Claude Code Is INSANE… But Is It Safe?
AI coding just went from “autocomplete my code” to “give me the entire repository and let me run the company.”
In this episode of CISO Tradecraft, G Mark Hardy and Ross Young break down what Claude Code can actually do, and the security implications that come with it.
Claude Code can read entire codebases, create and edit multiple files, run commands, execute tests, and operate like an AI developer sitting directly inside your environment.
But there’s a catch…
Every token costs money. And every permission creates risk.
We break down:
- 🔥 Tokenomics — How to get dramatically more AI coding for your dollar
- 🔥 PRDs — Why you should use powerful models to THINK before cheaper models BUILD
- 🔥 Security Risks — What happens when an AI agent can execute commands and modify your environment?
- 🔥 AI Licenses — Individual vs. enterprise and what CISOs need to worry about
- 🔥 Privacy & Regulated Data — When you may need offline or open-weight models
- 🔥 Harnesses — The policy-driven guardrails that can move security WAY earlier in the development process
- 🔥 MCP — How AI agents can connect to tools, systems, and data… and why permissions become a massive security issue
- 🔥 Agents & Skills — Serial vs. parallel agents, prompts, context, commands, hooks, and Markdown-based skills
- 🔥 Threat Modeling AI — Why you need to start threat modeling the prompts AND the tools
The big question isn't:
“Can AI write code?”
It absolutely can.
The question is:
“What happens when we give AI the keys to the kingdom?”
If you're a CISO, security leader, developer, or anyone trying to understand where agentic AI coding is heading, this episode is for you.
🎙️ Subscribe to CISO Tradecraft for more unfiltered conversations about cybersecurity, AI, leadership, and the future of the CISO.
Check out the Harness that Ross is building: