Join us at hack.lu 2026 — Info & Registration
Duration: 30 min
Type: Talk
Speakers: Andras Iklody
Abstract
In mid-2025, “vibe coding” was easy (and justified) to dismiss: impressive demos, questionable code (slop), horrendous security assumptions and a lot of overconfidence. I’ve talked about my own failures with it at last year’s hack.lu call for failures, this is meant as a follow-up to that. Since then, the agentic engineering landscape has changed dramatically, coding agents have become more capable, but the more important change is methodological: developers have started to learn how to scope, constrain, review, and reuse agent workflows in ways that resemble engineering rather than just aimlessly prompting.
This talk presents field notes from several months of applying agentic engineering to real security tooling work, especially around MISP and adjacent projects. It focuses on what changed since the early vibe-coding experiments, which misconceptions still hold us back, and which procedures made the difference between more efficient engineering and becoming a slop factory.
We will look at practical lessons around task scoping, risk-tiering, context management, reusable /skills, PRD-driven workflows, review loops, test generation, adversarial self-audits, and high-risk areas such as access control, API behavior, and performance-sensitive refactors. The goal is not to blindly flood everyone with AI-generated code and consider it trustworthy by default, but to show how security-conscious engineers can use agents without abandoning engineering judgment.
Attendees will leave with a realistic playbook for using AI agents in security software development: what to delegate, what to avoid, how to structure context, how to review outputs, and how to maintain - or improve on - the level of quality we were accustomed to in the before-times.
Description
My plan is to touch on the following topics for AI engineering:
- agentic processes
- a shift in where the human workload goes
- PRD based development
- documents as memory
- context management
- secure practices
- compertmentalisation
- risk tiers as a parralel to threat modelling
- methodology choices based on the task’s risk-tier
- using the AI for security vetting
- practical tips and tricks
- useful skills
- tooling
- keeping costs sane
- lessons learnt, what worked, what didn’t