AI Agents Are Pulling Random Code Off GitHub
Description
The biggest cybersecurity threat no one talks about: AI agents blindly pulling open-source packages with six layers of trust — and zero human review. Sam Lessin explains why AI speed + software supply chains = catastrophe. "It's six levels of trust removed. If you change two lines, you can steal everything." We’re also on ↓ X: https://twitter.com/moreorlesspod Instagram: https://instagram.com/moreorless Spotify: https://podcasters.spotify.com/pod/show/moreorlesspod Connect with us here: 1) Sam Lessin: https://x.com/lessin 2) Dave Morin: https://x.com/davemorin 3) Jessica Lessin: https://x.com/Jessicalessin 4) Brit Morin: https://x.com/brit
Summary
Generated by claude-haiku-4-5-20251001AI Agents Are Pulling Random Code Off GitHub - Summary
Main Topics
- Supply Chain Security Risk: The vulnerability created when AI agents automatically fetch and integrate code from GitHub without human verification
- Trust Chain Exploitation: How trust networks can be compromised at multiple levels
- Velocity vs. Security Tradeoff: The tension between faster AI-driven development and security due diligence
Key Points
- Traditional Software Development Model:
- Software packages contain code from multiple developers across the internet
- Users historically had limited visibility into dependency chains
- This created inherent risk, but slow velocity meant there was time for review processes
- The AI Agent Problem:
- AI agents autonomously search for and pull code from GitHub to fulfill specific capabilities
- This happens at much higher speeds than human developers working
- Minimal human oversight or verification of code sources
- Decision-making is automated: "I need X capability → finds package on GitHub → integrates it"
- Threat Model:
- Trust chains are typically 6+ levels deep (person A trusts person B who trusts person C, etc.)
- A malicious actor only needs to compromise one weak link in this chain
- Even minimal code changes (two lines) can enable data theft or system compromise
- The attacker doesn't need to compromise the original developer—just someone in the dependency chain
- The Core Issue:
- The traditional risk existed but was manageable due to human gatekeeping
- AI agents remove this human review layer while exponentially increasing integration velocity
Notable Quotes
> "It's six levels of trust removed that if you change two lines, you can steal everything."
> "Now you have AI agents running around looking for capabilities... Just pulling stuff out of GitHub off the internet and using it because you're going so much faster. You're moving faster. You're checking less."
> "You're able to do way more. But the cost is that there's all this implicit risk."
> "This is the premier question in security of the internet."
Takeaways
- Critical Security Gap: AI agents are outpacing security practices by automating dependency management without human verification
- Supply Chain Risk is Accelerating: The shift toward autonomous AI development significantly amplifies existing software supply chain vulnerabilities
- Need for Urgent Solutions: Organizations need to establish guardrails and verification processes for AI-driven code integration before widespread exploitation occurs
- This is a Systemic Problem: Not a flaw in any one tool, but a fundamental conflict between speed and security in the AI era
Transcript
It's six levels of trust removed that if you change two lines, you can steal everything. When you're using a piece of software, it almost certainly references inside it tons of people who developed it on the internet. And when you start using your thing, you don't know who they are. They're just random keys on the internet and someone trusted it and that person trusts someone and that person trusted six other people. So if you exploit any of those, you start including stuff in your software that you have no idea. It's six levels of trust removed that if you change two lines, you can steal everything. And this is how it's always worked. The velocity was low enough. And if you were including a new package, there was a process around you. Do I trust this? Now you have AI agents running around looking for capabilities. I need something that does this. Just pulling stuff out of GitHub off the internet and using it because you're going so much faster. You're moving faster. You're checking less. You're able to do way more. But the cost is that there's all this implicit risk. I think this is a super real thing. This is the premier question in security of the internet. They're just random keys on the internet and someone trusted it and that person trusts someone and that person trusted six other people. So if you exploit any of those, you start including stuff in your software that you have no idea. It's like six levels of trust removed that if you change two lines, you can steal everything. And this is how it's always worked. The velocity was low enough. And if you were like including a new package, there was like a process around you. Like, do I trust this? Now you have AI agents running around looking for capabilities. I need something that does this. Just pulling shit out of GitHub off the internet and using it because you're going so much faster. You're moving faster. You're checking less. You're able to do way more. But the cost is that there's all this implicit risk. I think this is a super real thing. This is the premier question in security of the internet connect to connect to connect to connect to connect to connect to connect to connect to connect to connect to connect connect to connect connect to connect connect to connect connect connect connect connect connect connect connect connect connect connect connect connect connect out.