Risky Biz Podcast: Open Source Risk Is Compounding as AI Agents Write 90% of New Code
Blog post from Socket
Socket CEO Feross Aboukhadijeh discusses with Casey Ellis on the Risky Business podcast the implications of AI agents increasingly writing production code, particularly in the context of open source security. As AI-generated code becomes predominant in AI labs and gains traction in enterprises, with reports suggesting up to 50% of code is now AI-generated, there arises a challenge in managing rapidly expanding dependency graphs that automatically incorporate open source packages without thorough risk evaluation. The conversation delves into potential vulnerabilities, such as worm-style npm compromises, and the balance between quickly applying patches and the risk of integrating unvetted code. Feross highlights the importance of install-time enforcement as a crucial control layer to prevent malicious packages from reaching production environments, underscoring the importance of this discussion for those involved in AI development and security.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 2 | 3,583 | 743 | 199 | -1% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.