AI Native DevCon 2026 London — all conference sessions as interactive skills
66
83%
Does it follow best practices?
Impact
—
No eval scenarios have been run
Risky
Do not use without reviewing
This public transcript is intentionally redacted. The source talk contained live demonstrations and concrete examples of unsafe skill behavior. Those sections have been replaced with non-operational summaries so the talk can be used for defensive education without publishing harmful mechanics.
Liran Tal, speaking from a security research perspective, discusses the emerging security model around agent skills. The introducer presents him as a secure-coding expert with a background in JavaScript and developer security.
Tal argues that agent skills should be treated as supply-chain components, not harmless documentation. A skill can contain instructions, references, supporting files, and natural-language behavior that an agent may trust once it is installed in a workspace.
The talk compares the early skill ecosystem to early package-registry growth: fast adoption, easy publishing, weak review habits, and limited integrity controls. Tal's concern is that natural-language artifacts can encode unsafe behavior in ways that traditional pattern matching may miss.
The talk's central model is the combination of three conditions:
Tal warns that any combination of these conditions increases risk, and all three together can create a serious failure mode. Shell access, persistent memory, broad tool permissions, and user approval fatigue can amplify the problem.
Tal challenges the audience to ask whether they actually read installed skills, supporting files, and updates. The point is that trusting a workspace often means the agent inherits trust in the files inside it. If a user approves broad permissions repeatedly, the approval step can stop acting as a meaningful boundary.
The original talk included several demonstrations of unsafe skill behavior and unsafe agent workflows. The public version does not include:
The safe lesson from those sections is that skill review must cover both obvious code-like content and natural-language instructions, including bundled references and future updates.
This redacted bundle supports conceptual discussion, security reviews, and policy design. It does not support reproducing the original demos or extracting operational attack details.
.tessl-plugin
talk-batey-building-product-teams-age-of-ai
talk-birgitta-closing-keynote
talk-debois-agent-enablement
talk-douglas-training-ai-on-your-own-code
talk-dubnov-merge-rate-ai-adoption
talk-farley-vibe-coding-best-we-can-do
talk-firtman-web-mcp-agentic-web
talk-foxwell-reinvention-dev-team
talk-graziano-spec-driven-development
talk-groetzinger-skills-everywhere
talk-jones-odevo-ai-native-transformation
talk-jourdan-pipelines-to-prompts
talk-katsioloudes-code-security-ai
talk-lamis-context-engineering-dreaming
talk-lawson-agent-experience
talk-luebken-embedding-pi-coding-agent
talk-maleix-collective-intelligence
talk-maple-ai-native-devcon-welcome-slick
talk-maple-ai-native-devcon-welcome-spec-reviewer
talk-maple-aind-devcon-welcome
talk-maple-context-engineering-skills
talk-maple-continuous-ai-github-workflows
talk-maple-harness-engineering
talk-maple-tldraw-ai-canvas-experiments
talk-marsden-agent-desktops
talk-martinelli-spec-driven-development
talk-moss-skills-team-workflow
talk-overweg-one-brain-no-filtering
talk-podjarny-skills-are-the-new-code
talk-roberts-ai-native-brownfield
talk-roberts-brownfield-ai-native
talk-scheire-artificial-intelligence
talk-selajev-docker-sandboxes-agents
talk-sloan-harness-engineering-beyond-code
talk-stack-humans-architect-ai-writes-code
talk-stoneham-product-brain
talk-tal-skills-security
talk-thomas-ai-native-engineering
talk-walter-runtime-intelligence-agents
talk-wilson-cq-stack-overflow-for-agents
talk-wotherspoon-humans-vs-slop