Your Coding Agent Just Installed a Package. Did Anyone Check the Name?
Real talk: how many of you have actually looked at every package name your AI coding assistant pulled in this week? Not "did you review the code it wrote." Did you check the dependency it decided to install. If the hon
Real talk: how many of you have actually looked at every package name your AI coding assistant pulled in this week?
Not "did you review the code it wrote." Did you check the dependency it decided to install.
If the honest answer is "no," you're not alone, and that's exactly the gap this SafeDev Talk is about.
๐๐ก๐ ๐ฉ๐๐ซ๐ญ ๐ง๐จ๐๐จ๐๐ฒ'๐ฌ ๐ญ๐๐ฅ๐ค๐ข๐ง๐ ๐๐๐จ๐ฎ๐ญ
Copilots used to draft. You'd read the suggestion, hit tab, move on. That was the trust model: AI proposes, human disposes.
Agentic tools don't work that way anymore. They install dependencies. They touch Dockerfiles. They trigger CI/CD steps. Sometimes all without a human in the loop at the exact moment it happens.
Code review, commit history, that little pause where someone glances at a diff, all of that was built assuming a person made the call. What happens when the thing making the call is an agent?
Why your SBOM might not have the answer
๐๐จ๐ฎ'๐ฏ๐ ๐ฉ๐ซ๐จ๐๐๐๐ฅ๐ฒ ๐ ๐จ๐ญ ๐ญ๐ก๐ ๐ญ๐จ๐จ๐ฅ๐ข๐ง๐ ๐๐ฅ๐ซ๐๐๐๐ฒ:
- SBOMs
- Dependency scanners
- CI/CD security gates
- Code review on every PR
Good tooling. Built on an assumption that's getting shakier: that a human decided what went into the build, and left a trail you can audit.
๐๐ซ๐ฒ ๐๐ง๐ฌ๐ฐ๐๐ซ๐ข๐ง๐ ๐ญ๐ก๐๐ฌ๐ ๐ฐ๐ข๐ญ๐ก ๐ฐ๐ก๐๐ญ ๐ฒ๐จ๐ฎ ๐ก๐๐ฏ๐ ๐ญ๐จ๐๐๐ฒ:
- Can you tell whether a developer or an agent installed a given dependency?
- Does your SBOM capture that distinction at all?
- If an agent commits and merges, does "code review" still mean what you think it means?
- What does shift-left even mean when the fastest-moving thing in your pipeline isn't a person?
If those questions make you pause, that's the point of this session.
๐๐ก๐๐ญ ๐ฐ๐'๐ซ๐ ๐๐๐ญ๐ฎ๐๐ฅ๐ฅ๐ฒ ๐๐จ๐ฏ๐๐ซ๐ข๐ง๐
This is a live, practitioner-led SafeDev Talk organized by Xygeni, not a slide deck about AI risk in the abstract. We're getting into:
- How "AI suggests" quietly became "AI acts" in real engineering teams
- What changes at the install moment when nobody checks the package name first
- Whether SBOMs and provenance hold up when an agent decided what goes into the build
- What's left of code review and shift-left when agents commit on their own
- What a secure agentic pipeline actually needs: tooling, process, and team culture
- Who should show up
If you're in AppSec, DevSecOps, platform engineering, or you're just the person on your team who already knows agents are touching dependencies and containers whether it's "officially allowed" or not, this one's for you.
๐
August 6th
โฐ 11:30 CEST
โก๏ธ Register here: https://www.linkedin.com/events/7485971126628675584/
Bring your worst "wait, did the agent actually do that?" story. We'll get into it live.
Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes โ full credit and traffic to the original publisher.