DEV Community

Cover image for Your Coding Agent Just Installed a Package. Did Anyone Check the Name?
Maria
Maria

Posted on

Your Coding Agent Just Installed a Package. Did Anyone Check the Name?

Real talk: how many of you have actually looked at every package name your AI coding assistant pulled in this week?

Not "did you review the code it wrote." Did you check the dependency it decided to install.

If the honest answer is "no," you're not alone, and that's exactly the gap this SafeDev Talk is about.

𝐓𝐡𝐞 𝐩𝐚𝐫𝐭 𝐧𝐨𝐛𝐨𝐝𝐲'𝐬 𝐭𝐚𝐥𝐤𝐢𝐧𝐠 𝐚𝐛𝐨𝐮𝐭

Copilots used to draft. You'd read the suggestion, hit tab, move on. That was the trust model: AI proposes, human disposes.

Agentic tools don't work that way anymore. They install dependencies. They touch Dockerfiles. They trigger CI/CD steps. Sometimes all without a human in the loop at the exact moment it happens.

Code review, commit history, that little pause where someone glances at a diff, all of that was built assuming a person made the call. What happens when the thing making the call is an agent?

Why your SBOM might not have the answer

𝐘𝐨𝐮'𝐯𝐞 𝐩𝐫𝐨𝐛𝐚𝐛𝐥𝐲 𝐠𝐨𝐭 𝐭𝐡𝐞 𝐭𝐨𝐨𝐥𝐢𝐧𝐠 𝐚𝐥𝐫𝐞𝐚𝐝𝐲:

  • SBOMs
  • Dependency scanners
  • CI/CD security gates
  • Code review on every PR

Good tooling. Built on an assumption that's getting shakier: that a human decided what went into the build, and left a trail you can audit.

𝐓𝐫𝐲 𝐚𝐧𝐬𝐰𝐞𝐫𝐢𝐧𝐠 𝐭𝐡𝐞𝐬𝐞 𝐰𝐢𝐭𝐡 𝐰𝐡𝐚𝐭 𝐲𝐨𝐮 𝐡𝐚𝐯𝐞 𝐭𝐨𝐝𝐚𝐲:

  • Can you tell whether a developer or an agent installed a given dependency?
  • Does your SBOM capture that distinction at all?
  • If an agent commits and merges, does "code review" still mean what you think it means?
  • What does shift-left even mean when the fastest-moving thing in your pipeline isn't a person?

If those questions make you pause, that's the point of this session.

𝐖𝐡𝐚𝐭 𝐰𝐞'𝐫𝐞 𝐚𝐜𝐭𝐮𝐚𝐥𝐥𝐲 𝐜𝐨𝐯𝐞𝐫𝐢𝐧𝐠

This is a live, practitioner-led SafeDev Talk organized by Xygeni, not a slide deck about AI risk in the abstract. We're getting into:

  • How "AI suggests" quietly became "AI acts" in real engineering teams
  • What changes at the install moment when nobody checks the package name first
  • Whether SBOMs and provenance hold up when an agent decided what goes into the build
  • What's left of code review and shift-left when agents commit on their own
  • What a secure agentic pipeline actually needs: tooling, process, and team culture
  • Who should show up

If you're in AppSec, DevSecOps, platform engineering, or you're just the person on your team who already knows agents are touching dependencies and containers whether it's "officially allowed" or not, this one's for you.

📅 August 6th
⏰ 11:30 CEST
➡️ Register here: https://www.linkedin.com/events/7485971126628675584/

Bring your worst "wait, did the agent actually do that?" story. We'll get into it live.

Top comments (0)