← Back to feed
AI SecurityEmerging1 sourceAug 16, 2026 · 21:04via Socket Security Blog

How AI Agents Expand the Software Supply Chain Attack Surface

Brief

At AI Council 2026 , Socket founder and CEO Feross Aboukhadijeh examined how coding agents are changing the software supply chain threat model. Agents can select dependencies, connect to MCP servers, install skills, and execute code with developer credentials, often without a human reviewing those decisions.

The talk highlights three important developments:

  • AI agents increasingly choose, install, and run third-party code.
  • Existing security infrastructure assumes humans make those trust decisions.
  • That infrastructure is struggling as development moves to machine speed.

Feross walks through several major supply chain attacks from 2026, including incidents involving Axios, TanStack, and Trivy.

Read more on Socket Security Blog