“There is no accountability”: AI coding agents are installing packages no one owns

TL;DR AI
2 min readKey summary
AI coding agents are increasingly installing packages, dependencies, plugins, and extensions on their own, creating a new supply-chain risk for companies.
Aikido Security says the core problem is accountability: no one clearly owns or reviews what autonomous tools add to the codebase.
The company launched Aikido Endpoint to inspect and block risky installs in real time, plus Aikido Infinite for continuous AI penetration testing.
The broader market is responding too, with vendors like Socket, Endor Labs, Chainguard, Snyk, Arcjet, and Mobb Security targeting different parts of the AI development attack surface.
