Dev.to AI ๐Ÿค– Ai ๐Ÿ‘ 0 ๐Ÿ“– 2 min read

Your Coding Agent Just Installed a Package. Did Anyone Check the Name?

Real talk: how many of you have actually looked at every package name your AI coding assistant pulled in this week? Not "did you review the code it wrote." Did you check the dependency it decided to install. If the hon

Real talk: how many of you have actually looked at every package name your AI coding assistant pulled in this week?

Not "did you review the code it wrote." Did you check the dependency it decided to install.

If the honest answer is "no," you're not alone, and that's exactly the gap this SafeDev Talk is about.

๐“๐ก๐ž ๐ฉ๐š๐ซ๐ญ ๐ง๐จ๐›๐จ๐๐ฒ'๐ฌ ๐ญ๐š๐ฅ๐ค๐ข๐ง๐  ๐š๐›๐จ๐ฎ๐ญ

Copilots used to draft. You'd read the suggestion, hit tab, move on. That was the trust model: AI proposes, human disposes.

Agentic tools don't work that way anymore. They install dependencies. They touch Dockerfiles. They trigger CI/CD steps. Sometimes all without a human in the loop at the exact moment it happens.

Code review, commit history, that little pause where someone glances at a diff, all of that was built assuming a person made the call. What happens when the thing making the call is an agent?

Why your SBOM might not have the answer

๐˜๐จ๐ฎ'๐ฏ๐ž ๐ฉ๐ซ๐จ๐›๐š๐›๐ฅ๐ฒ ๐ ๐จ๐ญ ๐ญ๐ก๐ž ๐ญ๐จ๐จ๐ฅ๐ข๐ง๐  ๐š๐ฅ๐ซ๐ž๐š๐๐ฒ:

  • SBOMs
  • Dependency scanners
  • CI/CD security gates
  • Code review on every PR

Good tooling. Built on an assumption that's getting shakier: that a human decided what went into the build, and left a trail you can audit.

๐“๐ซ๐ฒ ๐š๐ง๐ฌ๐ฐ๐ž๐ซ๐ข๐ง๐  ๐ญ๐ก๐ž๐ฌ๐ž ๐ฐ๐ข๐ญ๐ก ๐ฐ๐ก๐š๐ญ ๐ฒ๐จ๐ฎ ๐ก๐š๐ฏ๐ž ๐ญ๐จ๐๐š๐ฒ:

  • Can you tell whether a developer or an agent installed a given dependency?
  • Does your SBOM capture that distinction at all?
  • If an agent commits and merges, does "code review" still mean what you think it means?
  • What does shift-left even mean when the fastest-moving thing in your pipeline isn't a person?

If those questions make you pause, that's the point of this session.

๐–๐ก๐š๐ญ ๐ฐ๐ž'๐ซ๐ž ๐š๐œ๐ญ๐ฎ๐š๐ฅ๐ฅ๐ฒ ๐œ๐จ๐ฏ๐ž๐ซ๐ข๐ง๐ 

This is a live, practitioner-led SafeDev Talk organized by Xygeni, not a slide deck about AI risk in the abstract. We're getting into:

  • How "AI suggests" quietly became "AI acts" in real engineering teams
  • What changes at the install moment when nobody checks the package name first
  • Whether SBOMs and provenance hold up when an agent decided what goes into the build
  • What's left of code review and shift-left when agents commit on their own
  • What a secure agentic pipeline actually needs: tooling, process, and team culture
  • Who should show up

If you're in AppSec, DevSecOps, platform engineering, or you're just the person on your team who already knows agents are touching dependencies and containers whether it's "officially allowed" or not, this one's for you.

๐Ÿ“… August 6th
โฐ 11:30 CEST
โžก๏ธ Register here: https://www.linkedin.com/events/7485971126628675584/

Bring your worst "wait, did the agent actually do that?" story. We'll get into it live.

๐Ÿ“ฐ Read the original article on Dev.to AI

Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes โ€” full credit and traffic to the original publisher.