Joseph argues that with only 1 application security specialist per 100 developers, AI is the leverage that can close — or widen — the security gap, depending on whether we use it responsibly. Through a tour of practical demos he shows how to use AI to write safer code, leverage MCP servers and skills, make supply chain decisions, fix vulnerabilities faster in the PR, and educate developers — while being honest about hallucinations, non-determinism, and the limits of AI as a security tool. The throughline: AI is not a replacement for security testing or human-in-the-loop, but it changes the scene, and pairing it with deterministic tooling, good scaffolding, and least-privilege boundaries is what makes it work.
outline.md to locate the relevant section, then read that section of transcript.md.transcript.md. Never put quotation marks around paraphrased content.transcript.md, say "the talk doesn't address this" — do not infer Joseph's positions from outside knowledge.outline.md before attributing. Where the transcript clearly garbles a term (e.g. "Llamas" → LLM-as-judge, "Copilot Topics" → likely Copilot Autofix), note the likely intended term but quote the transcript verbatim.When the user asks "how would Joseph tackle ?" or wants the talk's framework applied to their own situation:
outline.md → "Named frameworks / concepts" to find the relevant approach (start-left, AI-as-reasoning-layer-on-top-of-deterministic-detection, MCP+skills layering, dual-LLM, task flows, security SLOs, etc.).transcript.md for Joseph's exact wording.When the user asks to "audit", "score", "review", or "gap-analyse" their AI-for-security setup against this talk — or describes their situation and asks where they're falling short:
outline.md → "Named frameworks / concepts" to locate the five areas Joseph covers: (1) writing safer code, (2) MCP servers + skills + agentic workflows, (3) supply chain decisions, (4) remediating alerts faster, (5) developer security education. Also use his MCP-vs-SAST comparison as a sub-framework.transcript.md and quote it verbatim when stating what "good" looks like.When the user asks to draft an artifact Joseph described — e.g. a supply-chain-decision instruction file, an agents.md, a task flow, an agentic workflow script, security SLOs for a dev team:
outline.md and the matching range of transcript.md.gh.io/sk (supply chain instruction files), gh.io/scg (hands-on training playground), gh.io/taskflows (vulnerability-finding task flows). Prefer extending those over inventing from scratch.[not from talk — added as a starting placeholder].For any question about what Joseph said, did, or argued:
outline.md first to find the relevant section(s).transcript.md.transcript.md. Do not paraphrase Joseph's words while presenting them as a quote.When the user's current work touches themes Joseph addressed — AI-assisted coding, MCP setup, agentic workflows, security review, supply chain risk, fixing vs detecting — even if they haven't asked about the talk:
transcript.md — one quote is usually enough.When the user wants to understand a concept Joseph covered (MCP, skills, agentic workflows, task flows, dual-LLM/LLM-jury, fuzzing with AI, start-left, "fixing problem not detection problem"):
outline.md → "Terminology glossary".transcript.md.quotes.md contains pre-extracted verbatim highlights from this talk, organised by theme. When formulating answers, check quotes.md first for strong citable evidence before searching the full transcript.md.
1887349
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.