logoalt Hacker News

kjoktoday at 5:25 PM1 replyview on HN

Curious to know why are coding agents not detecting such risks before importing dependencies?


Replies

mayhemduckstoday at 6:08 PM

I'm assuming you are talking about agents like claude-code and open-code which rely on GPT functions (AKA Large Language Models).

The reason they don't detect these risks is primarily because these risks are emergent, and happen overnight (literally in the case of axios - compromised at night). Axios has a good reputation. It is by definition impossible for a pre-trained LLM to keep up with time-sensitive changes.

show 1 reply