Tag: supply-chain

Posts with tag supply-chain

Agent Config Isn't Configuration. It's an Execution Surface

Agent Config Isn't Configuration. It's an Execution Surface

I audit dependencies. Lockfiles, advisories, the whole ritual. Then the keyv worm shipped its payload as committed agent config, and I realised I have no equivalent reflex for the files that configure the thing writing my code.

Aug 10, 20267 min read
Read more
AI code isn't dangerous at random

AI code isn't dangerous at random

I almost shipped a vulnerability to production because the model handed it to me with full confidence. Then I checked the numbers — the 2026 ones, not the two-year-old ones. Models hallucinate less, but picking a model stopped helping, and the attack surface is now shared by all of them.

Jul 3, 20267 min read
Read more
Tag: supply-chain | Code Nomad