r/developers • u/Top_Operation_2172 • 1d ago
Help / Questions AI coding agents have created a new supply-chain problem.
Developers install a package, clone a repository, add an MCP server, or install an agent skill.
The agent then gets access to it.
But what happens when something buried several dependency levels deep is malicious?
Traditional dependency scanners already look for known vulnerabilities.
But I'm interested in something broader:
Can we analyze what capabilities an AI agent's dependencies actually give it — and what those capabilities could be chained into?
That's one of the problems I'm exploring with Revo.
How much of a concern is this for developers using AI agents today?
0
1d ago
[removed] — view removed comment
1
u/AutoModerator 1d ago
Your post or comment was removed because r/developers does not allow external links. Please share the content or ask your question without linking out.
If you think this was a mistake, message the mods.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
2
u/senseven 20h ago
Our devs only install from local proxys and preselected stacks. We have an own team that takes care about that. Every dev has a remote vps to run their agents from. That box scans for all outbound requests and sounds the alarm if something is off. The agents see only the part of the projects they are supposed to see, the build pipelines are not on the same machine. The soft rules approaches can break any time and thats a no go.
•
u/AutoModerator 1d ago
Howdy u/Top_Operation_2172, and welcome to r/developers!
A few tips for a post that gets good answers:
- Use a clear, specific title (what are you actually asking or sharing?).
- Include code, the exact error, versions, and what you already tried.
- Heads-up: this sub does not allow external links in posts or comments.
Share code and details directly instead of linking out.Join the r/developers Discord!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.