
We reside in a world the place anybody can publish to npm or PyPI, and we’ve seen attackers slip malicious packages into these ecosystems or compromise ones which are broadly used. A number of the current incidents have concerned safety and devops instruments themselves pulling a compromised dependency, operating it as a part of CI/CD with elevated privileges, and quietly exfiltrating secrets and techniques or tampering with builds. I personally skilled the sort of compromise a few months in the past, and needed to replace all of my credentials in GitHub.
Pulling unvetted code is dangerous; now layer AI brokers on high of that. They default to no matter is best to find and combine. If a bundle solves an issue in entrance of the agent, the agent will add it. That is the outdated “obtain a random library from the Web” drawback, however now it’s on autopilot, at scale, and transferring at a tempo we’ve by no means seen earlier than.
To resolve this drawback, we should present the brokers with an innate sense of our threat tolerance, an accepted parts listing, our wishes round logging, and so on. We will do that with spec recordsdata and what the trade calls constitutions. Collectively, that is referred to as harness engineering, which we are going to speak extra about later.