Socket’s Feross Aboukhadijeh argues that AI agents widen open-source supply-chain risk because they can choose dependencies, run package-manager and MCP workflows, and act with developer credentials while maintainers and security teams are already dealing with compromised packages and AI-assisted vulnerability reports.
How AI Agents Expand the Software Supply Chain Attack Surface
Socket's Feross Aboukhadijeh argues that AI agents widen open-source supply-chain risk because they can choose dependencies, run package-manager and MCP workflows, and act with developer credentials while maintainers and security teams are already dealing with compromised packages and AI-assisted vulnerability reports.
Source: Socket