Switch language한국어
Back to the list

“There is no accountability”: AI coding agents are installing packages no one owns

TL;DR AI

Key summary

2 min read
  1. AI coding agents are increasingly installing packages, dependencies, plugins, and extensions on their own, creating a new supply-chain risk for companies.

  2. Aikido Security says the core problem is accountability: no one clearly owns or reviews what autonomous tools add to the codebase.

  3. The company launched Aikido Endpoint to inspect and block risky installs in real time, plus Aikido Infinite for continuous AI penetration testing.

  4. The broader market is responding too, with vendors like Socket, Endor Labs, Chainguard, Snyk, Arcjet, and Mobb Security targeting different parts of the AI development attack surface.

Read the original