Skip to content
Security & Trust Talking point

Wiz researcher warns coding agents can add dependencies developers may not know about

A Wiz researcher said that with coding agents, developers in many cases do not know what their code contains.

W
WebPulse Newsroom
AI-assisted · 2 min read
Share on X LinkedIn
Wiz researcher warns coding agents can add dependencies developers may not know about
In brief
  • Alon Schindel of Wiz said that when a coding agent writes the code, its author in many cases does not know what is inside it.
  • He argued that visibility into dependencies matters more now, and hoped coding agents will learn to favour safer choices.

Alon Schindel, who leads AI and threat research at Wiz, flagged a possible supply chain gap on Software Engineering Daily. He spoke in the episode "Security in the Age of Instant Exploits." Coding agents can bring in outside libraries that the developer did not pick. The risk may then sit in code its own author does not fully know.

What was said

Schindel was describing how companies can cut their exposure. His team scans public code repositories, build pipelines and GitHub Actions. These are automated workflows that build and ship code. He said many projects carry weaknesses. When a popular package has poor security habits, every organisation that uses it inherits the problem. "You can see this package as a ticking bomb," he said.

Then he turned to AI, almost as an aside. He suggested coding agents may be one reason package use is becoming less safe. His point was plain: "if you write your code with a coding agent, in many cases, you don't even know what's inside it." The agent adds the libraries, and in many cases the developer may not weigh them.

His answer was visibility and better choices. He pointed to vetting open source code and starting from a more secure SBOM. An SBOM, or software bill of materials, is a list of every component in an application. He hoped coding agents will learn to favour safer designs. He admitted this will not be easy, since few developers want to give up a popular library.

Why it matters

Our reading: review habits often assume the author chose the packages. If an agent chose them, that assumption breaks. A developer cannot vouch for a list they may not have read.

For engineering leaders, that points to a plain step. Treat the dependency list in agent-assisted work as something a person must review, not a by-product. For buyers, it suggests asking suppliers for a component list and who checked it. Schindel's warning about neglected, popular packages shows what such a review should look for.

The other side

Schindel gave no figures on how often agents add weak packages. He hedged his own claim, calling AI only one possible reason. His scanning work covered public projects in general, not agent-written code in particular. He spoke of agents getting better only as a hope.

He also argued that defenders come out ahead overall, because they hold richer context about what they protect, and he believes that gives them the edge over attackers. The excerpts do not tie that view to dependencies in particular.

Written by the WebPulse Newsroom with AI assistance, and checked by our editorial review: every quotation was verified against the recording's transcript. How we use AI.

The conversation this talking point comes from

Share this insight