Key Info
Perplexity shared how it engineers safeguards for AI agents across its infrastructure, harnesses, and tools, and open-sourced Bumblebee, a read-only scanner for macOS and Linux that detects risky packages, extensions, and AI tool configurations.
Highlights
- Bumblebee scans developer machines for risky packages, extensions, and AI tool configs; connected to the "Computer" system it can trigger deeper scans when a new supply-chain risk emerges
- Computer reviews findings from Bumblebee and Numbat and proposes better detection rules, but humans must approve every change before it ships — agents cannot approve their own changes
- Perplexity's Secure Intelligence Institute collaborates with researchers at Stanford, CMU, Duke, Columbia, Ohio State, and UVA
- The company is also working with NVIDIA and the Open Secure AI Alliance, sharing tools and findings so others can strengthen their own systems