AI Native DevCon 2026 London — all conference sessions as interactive skills
71
89%
Does it follow best practices?
Impact
—
No eval scenarios have been run
Risky
Do not use without reviewing
Joseph argues that with only 1 application security specialist per 100 developers, AI is the leverage that can close — or widen — the security gap, depending on whether we use it responsibly. Through a tour of practical demos he shows how to use AI to write safer code, leverage MCP servers and skills, make supply chain decisions, fix vulnerabilities faster in the PR, and educate developers — while being honest about hallucinations, non-determinism, and the limits of AI as a security tool. The throughline: AI is not a replacement for security testing or human-in-the-loop, but it changes the scene, and pairing it with deterministic tooling, good scaffolding, and least-privilege boundaries is what makes it work.
outline.md to locate the relevant section, then read that section of transcript.md.transcript.md. Never put quotation marks around paraphrased content.transcript.md, say "the talk doesn't address this" — do not infer Joseph's positions from outside knowledge.outline.md before attributing. Where the transcript clearly garbles a term (e.g. "Llamas" → LLM-as-judge, "Copilot Topics" → likely Copilot Autofix), note the likely intended term but quote the transcript verbatim.When the user asks "how would Joseph tackle ?" or wants the talk's framework applied to their own situation:
outline.md → "Named frameworks / concepts" to find the relevant approach (start-left, AI-as-reasoning-layer-on-top-of-deterministic-detection, MCP+skills layering, dual-LLM, task flows, security SLOs, etc.).transcript.md for Joseph's exact wording.When the user asks to "audit", "score", "review", or "gap-analyse" their AI-for-security setup against this talk — or describes their situation and asks where they're falling short:
outline.md → "Named frameworks / concepts" to locate the five areas Joseph covers: (1) writing safer code, (2) MCP servers + skills + agentic workflows, (3) supply chain decisions, (4) remediating alerts faster, (5) developer security education. Also use his MCP-vs-SAST comparison as a sub-framework.transcript.md and quote it verbatim when stating what "good" looks like.When the user asks to draft an artifact Joseph described — e.g. a supply-chain-decision instruction file, an agents.md, a task flow, an agentic workflow script, security SLOs for a dev team:
outline.md and the matching range of transcript.md.gh.io/sk (supply chain instruction files), gh.io/scg (hands-on training playground), gh.io/taskflows (vulnerability-finding task flows). Prefer extending those over inventing from scratch.[not from talk — added as a starting placeholder].For any question about what Joseph said, did, or argued:
outline.md first to find the relevant section(s).transcript.md.transcript.md. Do not paraphrase Joseph's words while presenting them as a quote.When the user's current work touches themes Joseph addressed — AI-assisted coding, MCP setup, agentic workflows, security review, supply chain risk, fixing vs detecting — even if they haven't asked about the talk:
transcript.md — one quote is usually enough.When the user wants to understand a concept Joseph covered (MCP, skills, agentic workflows, task flows, dual-LLM/LLM-jury, fuzzing with AI, start-left, "fixing problem not detection problem"):
outline.md → "Terminology glossary".transcript.md.quotes.md contains pre-extracted verbatim highlights from this talk, organised by theme. When formulating answers, check quotes.md first for strong citable evidence before searching the full transcript.md.
.tessl-plugin
talk-azriel-executable-specs-agentic-coding
talk-batey-building-product-teams-age-of-ai
talk-birgitta-closing-keynote
talk-cormack-tests-lie-observability-ai-honest
talk-debois-agent-enablement
talk-douglas-training-ai-on-your-own-code
talk-dubnov-merge-rate-ai-adoption
talk-farley-vibe-coding-best-we-can-do
talk-firtman-web-mcp-agentic-web
talk-foxwell-reinvention-dev-team
talk-graziano-spec-driven-development
talk-groetzinger-skills-everywhere
talk-jones-odevo-ai-native-transformation
talk-jourdan-pipelines-to-prompts
talk-katsioloudes-code-security-ai
talk-kerr-bipolar-disorder-dysregulation-ai
talk-lamis-context-engineering-dreaming
talk-lawson-agent-experience
talk-lopopolo-harness-engineering-humans-steer-agents-execute
talk-luebken-embedding-pi-coding-agent
talk-maleix-collective-intelligence
talk-marsden-agent-desktops
talk-martinelli-spec-driven-development
talk-moss-skills-team-workflow
talk-obstbaum-willoughby-evals-hard
talk-overweg-one-brain-no-filtering
talk-podjarny-skills-are-the-new-code
talk-roberts-ai-native-brownfield
talk-roberts-brownfield-ai-native
talk-scheire-artificial-intelligence
talk-selajev-docker-sandboxes-agents
talk-sloan-harness-engineering-beyond-code
talk-smith-connecting-context-future-transports
talk-stack-humans-architect-ai-writes-code
talk-stoneham-product-brain
talk-syme-agentic-repository-automation
talk-tal-skills-security
talk-thomas-ai-native-engineering
talk-trieloff-browser-agents
talk-walter-runtime-intelligence-agents
talk-wilson-cq-stack-overflow-for-agents
talk-wotherspoon-humans-vs-slop