How to secure AI agents with defense in depth
Blog post from Doppler
AI agents create expanded security risks because they can interpret untrusted natural-language content, use external tools, access repositories and credentials, and take actions that may be redirected through prompt injection, compromised MCP tools, or overly broad permissions. The proposed defense-in-depth approach combines least-privilege tool access, separation of trusted instructions from external content, policy checks on sensitive actions, isolated runtimes, network and credential proxies, MCP gateways, and detailed audit logging, recognizing that no individual control can prevent every attack. The post emphasizes secrets management as a containment layer, arguing that centrally governed, narrowly scoped, short-lived credentials reduce the impact and reuse value of leaked secrets compared with persistent keys. It outlines five secrets-management pillars—centralized storage, access governance, secure delivery, lifecycle automation and dynamic credentials, and visibility—and presents Doppler as a platform for issuing and monitoring temporary credentials, such as time-bound AWS access, within AI-assisted development workflows.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 33 | 1,002 | 214 | 87 | -60% |
| AI Agents | 9 | 2,716 | 579 | 174 | -60% |
| MCP | 8 | 3,789 | 413 | 151 | -65% |
| AI Coding Assistant | 1 | 741 | 214 | 85 | -59% |
| Harness engineering | 1 | 93 | 59 | 29 | -64% |
| Observability | 1 | 1,527 | 341 | 123 | -63% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.