BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: MalSkill Lab: Hands-On Natural Language Malware in A
 I Agent\n   Orchestration Systems\n   Tags: AI | DEF CON Demo Labs | Inter
 mediate | AppSec | Defense/Blue\n   Team | Malware | Offense/Red Team | Pu
 rple Team | SecOps | Threat\n   Intel/Hunting | DEF CON Demo Labs\n   When
 : Saturday\, Aug 8\, 13:00 - 13:45 PDT\n   Where: LVCCW Level 1 Hall 3 100
 2 (Demo Labs Track 2) - [1]Map\n\n   Description:\n\n   Your AI agent trus
 ts every skill in its directory. What if one of them\n   is lying? In this
  Demo Lab\, I walk you through MalSkills\, natural\n   language malware pl
 anted inside AI agent skill systems. No binaries\,\n   no shellcode\, no s
 ignatures. Just English sentences with OS-level\n   access. Using ORPHEUS\
 , my open-source multi-skill orchestration\n   framework\, I demonstrate t
 hree escalating attacks live: 1. BURIED\n   INSTRUCTION: A malicious sente
 nce hidden in a legitimate skill\n   exfiltrates .env files on first execu
 tion. I show you 12 skills and\n   challenge you to spot it. 2. CHAIN ATTA
 CK: Five individually benign\n   skills that\, when orchestrated together\
 , create an emergent data\n   exfiltration path. No single skill is malici
 ous. The composition is\n   the weapon. 3. PERSISTENT GHOST: A skill that 
 writes itself into agent\n   memory\, surviving file deletion and session 
 restarts. Remove the\n   skill\, restart the agent\, exfiltration continue
 s. After offense\, I\n   flip to defense. I demo the MalSkill Detection To
 olkit: skill\n   integrity verification\, capability-based sandboxing\, or
 chestration\n   graph analysis\, and runtime behavioral monitoring. Attend
 ees leave\n   with: the ORPHEUS framework\, a MalSkill sample pack\, and a
  detection\n   toolkit\, all open source! Every AI agent with a plugin sys
 tem is\n   vulnerable today. Come see why.\n\n   SpeakerBio:  Nur "Burrito
 TheNurrito" Gucu\n\n   Offensive security professional and AI security res
 earcher with 10+\n   years across financial services\, startups\, and Amaz
 on. Currently on\n   the foundational model red team at Amazon AGI Labs\, 
 where I break AI\n   systems and build the tooling to detect what I find. 
 Core focus: LLM\n   security\, agentic system exploitation\, and the gaps 
 between how AI\n   frameworks are designed and how they actually behave un
 der adversarial\n   pressure. 6 patent applications. Published author (AWS
  Security Blog\,\n   internal science papers). Invited speaker on MCP secu
 rity and LLM\n   training APT attack surfaces. I turn research into shippe
 d products\n   and open-source tools\, not empty slide decks.\n\n   Links:
 \n       GitHub - [2]https://github.com/nuryslyrt/ORPHEUS\n   '\n\n   1. #
 LVCCW_Level1_Hall3\n   2. https://github.com/nuryslyrt/ORPHEUS\n\n\n
DTEND:20260808T204500Z
DTSTART:20260808T200000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)
SUMMARY:MalSkill Lab: Hands-On Natural Language Malware in AI Agent Orchest
 ration Systems
END:VEVENT
END:VCALENDAR
