We Vetted 2,000 AI Skills Before They Reached Developers
Lucas Palma
- When
- Thursday, July 21:55 PM – 2:15 PM · 20 min
- Where
- Track 3San Francisco, CA · imported from ai.engineer's public schedule feed
About this session
AI skills and plugins are becoming part of the software supply chain. They steer agent behavior, describe tools, run commands, access files, and shape how developers build with AI. Treating them as harmless configuration is a mistake. This talk shares what we learned from building an automated security review system for more than 2,000 internal AI skills before they reached a company wide plugin marketplace. I will walk through the risks we found, the checks that worked, the checks that created noise, and how we turned skill review into something developers could run locally and in CI. We will cover practical patterns for reviewing unsafe instructions, destructive commands, sensitive data exposure, risky tool use, credential handling, external calls, and agent behavior drift. The goal is to help AI engineers think about skills, plugins, and agent instructions as production dependencies that deserve review before they reach real users.
Speaker
Information Security Manager, Nubank
Lucas Palma is an Information Security Manager at Nubank, one of the world’s largest digital financial services platforms, where he leads Product Security across Application Security, Mobile Security, AI Security, and Product Security Engineering. He works at the intersection of software engineering, product security, and AI, helping teams adopt AI safely without slowing down product development. His current work focuses on securing AI adoption at enterprise scale, including AI coding assistants, agentic workflows, MCP integrations, secure coding guidance, AI security tooling, and automated security review inside developer workflows. He has more than 15 years of experience in information security, software engineering, and financial services, with work ranging from building security programs from scratch to reducing banking malware incidents by 90 percent through layered mobile protections. Lucas is passionate about making security practical for engineers by turning real attack patterns into guardrails, automation, evaluations, and tools that help teams ship faster and safer.
More in AI in Finance
- ALPHALAB: Autonomous Multi-Agent Research Across Optimization Domains with Frontier LLMsThursday, July 2 · 10:45 AM – 11:05 AM · Track 3
- Why Off-the-Shelf AI Doesn't Understand MoneyThursday, July 2 · 11:10 AM – 11:30 AM · Track 3
- Let's integrate AI Agents in Event-Sourced SystemsThursday, July 2 · 11:40 AM – 12:00 PM · Track 3
- How Kepler Built Verifiable AI for Financial ServicesThursday, July 2 · 12:05 PM – 12:25 PM · Track 3
- Build for the Memo, Not the Demo — Notes from 200 Investment CommitteesThursday, July 2 · 1:30 PM – 1:50 PM · Track 3
For developers: this programme is open data — JSON, iCal, schedule XML and an MCP endpoint.Show endpointsHide
- JSONEvery published session and speaker, in one request./aie-worldsfair-2026-import/feed.json
- iCalSubscribe in Google, Apple or Outlook Calendar./aie-worldsfair-2026-import/feed.ics
- Schedule XMLfrab / pentabarf — the format conference apps import./aie-worldsfair-2026-import/feed.xml
- MCP + RESTPoint Claude at the programme. OpenAPI 3.1 included./agents
No key, no signup, CORS open. Everything here is generated from the same data the organisers edit.