Home / Companies / Socket / Blog / Post Details
Content Deep Dive

How AI Agents Expand the Software Supply Chain Attack Surface

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
250
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

At AI Council 2026, Socket founder and CEO Feross Aboukhadijeh discussed how AI coding agents are expanding software supply chain risks by autonomously selecting dependencies, connecting to MCP servers, installing skills, and executing third-party code using developer credentials. He argued that security systems designed around human trust decisions are struggling to keep pace with automated development, citing 2026 attacks involving Axios, TanStack, and Trivy that used compromised maintainers, malicious transitive dependencies, prompt injection, and trusted tools. The presentation also examines risks from MCP servers, agent skills, and IDE extensions, as well as the pressure AI-enabled vulnerability discovery places on security teams, while offering an optimistic view that AI can also help defenders analyze open-source code, prioritize relevant vulnerabilities, and improve software security.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.