CtrlK
BlogDocsLog inGet started
Tessl Logo

ainativedev/aidevcon-2026-ldn

AI Native DevCon 2026 London — all conference sessions as interactive skills

69

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

outline.mdtalk-tal-skills-security/

Outline -- Your AI Agent Installed Malware Because a SKILL.md Told It To

Speaker: Liran Tal (Snyk)

Thesis

AI-agent skills should be reviewed like dependencies because they can affect agent behavior, data exposure, and action surfaces.

Concept Map

  1. Skills as supply-chain artifacts
  2. Provenance and ownership review
  3. Permission and data-access boundaries
  4. Sandboxed, least-privilege execution
  5. Semantic review beyond simple pattern matching
  6. Warning fatigue and approval design

Safe Application

  • Create a skill intake checklist.
  • Review what data a skill can expose and what actions it can influence.
  • Prefer sandboxed execution and explicit approval boundaries.
  • Use semantic review to understand behavior, not only filenames or keywords.

Not Included

Concrete live-demo mechanics, payload details, secret paths, and step-by-step misuse examples are not included in this published bundle.

README.md

tile.json