BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//speaker//P8RSGF
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251021T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:From Call for Failures to Slop Control: Agentic Engineering for Se
 curity Tooling - Andras Iklody
DTSTART;TZID=Europe/Luxembourg:20261021T083000
DTEND;TZID=Europe/Luxembourg:20261021T090000
DTSTAMP:20261009T050416Z
UID:pretalx-hack-lu-2026-QENAUY@pretalx.com
DESCRIPTION:In mid-2025\, "vibe coding" was easy (and justified) to dismis
 s: impressive demos\, questionable code (slop)\, horrendous security assum
 ptions and a lot of overconfidence. I've talked about my own failures with
  it at last year's hack.lu call for failures\, this is meant as a follow-u
 p to that. Since then\, the agentic engineering landscape has changed dram
 atically\, coding agents have become more capable\, but the more important
  change is methodological: developers have started to learn how to scope\,
  constrain\, review\, and reuse agent workflows in ways that resemble engi
 neering rather than just aimlessly prompting.\n\nThis talk presents field 
 notes from several months of applying agentic engineering to real security
  tooling work\, especially around MISP and adjacent projects. It focuses o
 n what changed since the early vibe-coding experiments\, which misconcepti
 ons still hold us back\, and which procedures made the difference between 
 more efficient engineering and becoming a slop factory.\n\nWe will look at
  practical lessons around task scoping\, risk-tiering\, context management
 \, reusable /skills\, PRD-driven workflows\, review loops\, test generatio
 n\, adversarial self-audits\, and high-risk areas such as access control\,
  API behavior\, and performance-sensitive refactors. The goal is not to bl
 indly flood everyone with AI-generated code and consider it trustworthy by
  default\, but to show how security-conscious engineers can use agents wit
 hout abandoning engineering judgment.\n\nAttendees will leave with a reali
 stic playbook for using AI agents in security software development: what t
 o delegate\, what to avoid\, how to structure context\, how to review outp
 uts\, and how to maintain - or improve on - the level of quality we were a
 ccustomed to in the before-times.
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2026/talk/QENAUY/
END:VEVENT
END:VCALENDAR
