CtrlK
BlogDocsLog inGet started
Tessl Logo

ainativedev/latest-aidevcon-speakers-london-2026

AI Native DevCon 2026 London — all conference sessions as interactive skills

66

Quality

83%

Does it follow best practices?

Impact

No eval scenarios have been run

SecuritybySnyk

Risky

Do not use without reviewing

Overview
Quality
Evals
Security
Files

outline.mdtalk-tal-skills-security/

Outline - Skills Security

Speaker

Liran Tal, security researcher and developer advocate, discusses agent skill security at AI Native DevCon.

Safety Status

This outline describes a safety-redacted public version of the talk. Demonstration mechanics and unsafe examples have been removed.

Thesis

Agent skills are part of the software supply chain. They need review, provenance, isolation, and operational limits because agents may treat skill instructions and bundled files as trusted guidance.

Section Map

  1. Speaker introduction and audience framing.
  2. Why installed skills need actual review.
  3. Skills as more than a single markdown file.
  4. Missing controls in early skill ecosystems.
  5. The toxic-flow model: private context, untrusted input, and outbound communication.
  6. Approval fatigue and the limits of human confirmation.
  7. Supply-chain parallels: easy publishing, fast adoption, and weak update review.
  8. Redacted unsafe demonstrations.
  9. Why simple pattern matching is not enough.
  10. Defensive posture: review, isolate, constrain, and monitor.

Concepts

  • Skill as supply-chain artifact: A skill can influence agent behavior through instructions, references, and bundled content.
  • Toxic flow: Risk rises when an agent can combine private context, untrusted input, and outbound communication.
  • Approval fatigue: Repeated permission prompts can become ineffective when users accept them without review.
  • Review depth: Review should include metadata, body instructions, supporting files, and updates.
  • Hard boundary: Real security depends on permission limits, isolation, and policy enforcement, not prompt text alone.

Not Included

  • Harmful demonstration examples.
  • Hidden-instruction examples.
  • Operational abuse paths.
  • Runnable snippets.
  • Third-party delivery details.
  • Exact wording from unsafe demonstration material.

Safe Use

Use this talk to discuss governance, skill review, permission design, and agent risk modeling. Do not use it as a source for offensive mechanics.

README.md

tile.json