Andras Iklody
Andras Iklody works at the Luxembourgian Computer Security Incident Response Team (CSIRT) CIRCL as a software engineer and has been leading the development of the MISP core since early 2013. These days he's found a new passion in agentic engineering and micro-managing his loyal army of AI agents. He is a firm believer that there are no problems that cannot be tackled by building the right tool.
Session
In mid-2025, "vibe coding" was easy (and justified) to dismiss: impressive demos, questionable code (slop), horrendous security assumptions and a lot of overconfidence. I've talked about my own failures with it at last year's hack.lu call for failures, this is meant as a follow-up to that. Since then, the agentic engineering landscape has changed dramatically, coding agents have become more capable, but the more important change is methodological: developers have started to learn how to scope, constrain, review, and reuse agent workflows in ways that resemble engineering rather than just aimlessly prompting.
This talk presents field notes from several months of applying agentic engineering to real security tooling work, especially around MISP and adjacent projects. It focuses on what changed since the early vibe-coding experiments, which misconceptions still hold us back, and which procedures made the difference between more efficient engineering and becoming a slop factory.
We will look at practical lessons around task scoping, risk-tiering, context management, reusable /skills, PRD-driven workflows, review loops, test generation, adversarial self-audits, and high-risk areas such as access control, API behavior, and performance-sensitive refactors. The goal is not to blindly flood everyone with AI-generated code and consider it trustworthy by default, but to show how security-conscious engineers can use agents without abandoning engineering judgment.
Attendees will leave with a realistic playbook for using AI agents in security software development: what to delegate, what to avoid, how to structure context, how to review outputs, and how to maintain - or improve on - the level of quality we were accustomed to in the before-times.