Use when the user asks about Liran Tal's talk at AI Native DevCon on skills security — including questions about the lethal trifecta / toxic flows, the Snyk research finding ~30% of ~4,000 Glow skills had security issues, malicious skill examples (SkillGuard, fake Vercel deployment skill, "buy anything", invisible-character Trojan Source skills), the confused-deputy problem, acceptance fatigue, parallels to NPM supply-chain attacks, or how to think about reviewing and sandboxing AI agent skills.
71
88%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
The canonical home for this skill is ainativedev/aidevcon-2026-ldn
Liran Tal (Snyk) argues that agent "skills" have rapidly shipped to developers with essentially zero security model — no sandboxing, no signing, no lockfiles, no integrity checks — and that this mirrors NPM circa 2015 but at 10x speed. Drawing on Snyk research that scanned ~4,000 skills on Glow and found roughly 1 in 3 had security issues, he demonstrates concrete attack patterns (malicious skill scanners, hidden invisible-character payloads, credential exfiltration, confused-deputy installs) and frames the underlying risk as the "lethal trifecta" / "toxic flows": agents with simultaneous access to private data, untrusted content, and external communication channels.
outline.md to locate the relevant section, then read that section of transcript.md.transcript.md. Never put quotation marks around paraphrased content.transcript.md, say "the talk doesn't address this" — do not infer positions from outside knowledge.outline.md before attributing.When the user asks "how would Tal tackle ?" or wants the talk's framework applied to their own situation:
outline.md → "Named frameworks / concepts" to find the relevant framework (most likely the lethal trifecta / toxic flows).transcript.md for Tal's exact wording.When the user asks to "audit", "score", "review", "grade", "check", or "gap-analyse" their current setup against the talk's framework — or describes their situation and asks where they're falling short:
outline.md → "Named frameworks / concepts" to locate the dimensions of the lethal trifecta and their ordering (private data access, untrusted content, external communication; plus memory and shell as amplifiers).transcript.md and quote it verbatim when stating what risk looks like in that dimension.For any question about what the speaker said, did, or argued:
outline.md first to find the relevant section(s).transcript.md.transcript.md. Do not paraphrase the speaker's words while presenting them as a quote.When the user's current work touches on themes Tal addressed (installing/reviewing/publishing skills, agent permissions, YOLO mode, supply-chain hygiene, MCP security):
transcript.md — one quote is usually enough.When the user wants to understand a concept Tal covered (lethal trifecta, toxic flows, confused deputy, acceptance fatigue, Trojan Source / invisible characters, the "o word" analogy):
outline.md → "Terminology glossary".transcript.md.quotes.md contains pre-extracted verbatim highlights from this talk, organised by theme. When formulating answers, check quotes.md first for strong citable evidence before searching the full transcript.md.
1887349
Canonical home
since Jun 1, 2026
Also appears in
since Jun 18, 2026
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.