AI Native DevCon 2026 London — all conference sessions as interactive skills
68
85%
Does it follow best practices?
Impact
—
No eval scenarios have been run
Risky
Do not use without reviewing
Liran Tal (Snyk) argues that agent "skills" have rapidly shipped to developers with essentially zero security model — no sandboxing, no signing, no lockfiles, no integrity checks — and that this mirrors NPM circa 2015 but at 10x speed. Drawing on Snyk research that scanned ~4,000 skills on Glow and found roughly 1 in 3 had security issues, he demonstrates concrete attack patterns (malicious skill scanners, hidden invisible-character payloads, credential exfiltration, confused-deputy installs) and frames the underlying risk as the "lethal trifecta" / "toxic flows": agents with simultaneous access to private data, untrusted content, and external communication channels.
outline.md to locate the relevant section, then read that section of transcript.md.transcript.md. Never put quotation marks around paraphrased content.transcript.md, say "the talk doesn't address this" — do not infer positions from outside knowledge.outline.md before attributing.When the user asks "how would Tal tackle ?" or wants the talk's framework applied to their own situation:
outline.md → "Named frameworks / concepts" to find the relevant framework (most likely the lethal trifecta / toxic flows).transcript.md for Tal's exact wording.When the user asks to "audit", "score", "review", "grade", "check", or "gap-analyse" their current setup against the talk's framework — or describes their situation and asks where they're falling short:
outline.md → "Named frameworks / concepts" to locate the dimensions of the lethal trifecta and their ordering (private data access, untrusted content, external communication; plus memory and shell as amplifiers).transcript.md and quote it verbatim when stating what risk looks like in that dimension.For any question about what the speaker said, did, or argued:
outline.md first to find the relevant section(s).transcript.md.transcript.md. Do not paraphrase the speaker's words while presenting them as a quote.When the user's current work touches on themes Tal addressed (installing/reviewing/publishing skills, agent permissions, YOLO mode, supply-chain hygiene, MCP security):
transcript.md — one quote is usually enough.When the user wants to understand a concept Tal covered (lethal trifecta, toxic flows, confused deputy, acceptance fatigue, Trojan Source / invisible characters, the "o word" analogy):
outline.md → "Terminology glossary".transcript.md..tessl-plugin
talk-batey-building-product-teams-age-of-ai
talk-debois-agent-enablement
talk-douglas-training-ai-on-your-own-code
talk-dubnov-merge-rate-ai-adoption
talk-farley-vibe-coding-best-we-can-do
talk-firtman-web-mcp-agentic-web
talk-foxwell-reinvention-dev-team
talk-groetzinger-skills-everywhere
talk-jones-odevo-ai-native-transformation
talk-jourdan-pipelines-to-prompts
talk-katsioloudes-code-security-ai
talk-lamis-context-engineering-dreaming
talk-lawson-agent-experience
talk-luebken-embedding-pi-coding-agent
talk-maleix-collective-intelligence
talk-maple-ai-native-devcon-welcome-slick
talk-maple-ai-native-devcon-welcome-spec-reviewer
talk-maple-aind-devcon-welcome
talk-maple-harness-engineering
talk-maple-tldraw-ai-canvas-experiments
talk-marsden-agent-desktops
talk-martinelli-spec-driven-development
talk-moss-skills-team-workflow
talk-overweg-one-brain-no-filtering
talk-podjarny-skills-are-the-new-code
talk-scheire-artificial-intelligence
talk-sloan-harness-engineering-beyond-code
talk-stack-humans-architect-ai-writes-code
talk-stoneham-product-brain
talk-tal-skills-security
talk-walter-runtime-intelligence-agents
talk-wilson-cq-stack-overflow-for-agents
talk-wotherspoon-humans-vs-slop