Skip to Content
Prompts, skills and agents - a reality to check on why it starts with education.

Prompts, skills and agents - a reality to check on why it starts with education.

9/3/26, 3:30 PM - 9/3/26, 4:00 PM (Europe/Berlin) (30 minutes)
Prompts, skills and agents - a reality to check on why it starts with education.
Konstantin Graf
CEO at CHAINSTEP GmbH
Konstantin Graf
CEO at CHAINSTEP GmbH
Konstantin Graf is the CEO of the Hamburg-based technology consultancy CHAINSTEP GmbH and a proven expert in implementing Artificial Intelligence and Web3 technologies within mid-sized enterprises. Following years of leadership experience in international tech consulting, his current focus is guiding traditional industries through digital transformation. Through innovative solutions, including privacy-compliant language models and practical low-code frameworks, he demonstrates how companies can safely, efficiently, and sustainably integrate AI potential into their existing value chains.

An agent is not a chatbot with better manners. It reads content nobody reviewed, calls tools through MCP servers, and acts on behalf of employees — with their permissions. The attack surface shifts: the PDF, the ticket, the web page become the command line.

This talk uses examples to show how indirect prompt injection works, why the combination of data access and untrusted content  is the real danger zone, and what risks MCP integrations bring: over-broad permissions, poisoned tool descriptions, unvetted community servers, missing auditability.

The uncomfortable point: there is no patch. No filter reliably tells user intent from data. What remains are architectural decisions — and people who understand what they are deploying. Agent security starts with education, not with the SOC.