2026-10-11 16:37 UTC

The authors of arXiv:2609.07754 reportedly find that AI coding assistants almost never check supply-chain trust signals, potentially making explicit dependency-trust checks necessary in coding-agent workflows.

state: watchingheat: lowuncertainty: highconvergesscott: lowcoding-agents agentic-security software-supply-chain

What is this?

The paper is now identified: arXiv:2609.07754, 'Do AI Coding Assistants Check Before They Install? A Pre-Registered Demand-Side Audit of Trust Signals in the Research Software Supply Chain', authored by Pengyin Shan (submitted 7 Sep 2026, cs.CR), whose bibliography shows prior 2026 work auditing research-software citation metadata and situates the study in a small cluster of agent-security audits (weaponized setup instructions, in-band governance-signal compliance, provenance sensitivity). Secondary coverage (Quantum Zeitgeist) reports the design as 1,920 registered trials in which assistants verified origin trust signals such as SBOMs or signatures in under 1% of trials — consistent with the HN title's 'almost never' — and a LinkedIn post by Skip Sanzeri independently references the testing. What the supplied snippets still do not establish: which assistants were tested, how 'checking' was operationalized, and any independent examination or replication beyond one secondary outlet and one social mention. The surrounding coverage does document the threat environment the paper addresses — a Cloud Security Alliance note on skills-marketplace compromise and SANDWORM_MODE typosquatted npm packages deploying rogue MCP servers, and CSO Online on DPRK-crafted packages and 'slopsquatting' of hallucinated dependencies, with explicit guidance that agents should not install dependencies without developer review.

Why it matters to Scott

The grounding upgrade is real: a named author, a pre-registered 1,920-trial design, and a <1% verification headline make this the first quantified dated receipt for the premise of Architecture Not Vibes and Trust Hierarchy — model cooperation is not a control, so install-boundary checks must be enforced — and the pre-registration itself speaks Scott's Falsifiability Spine. But it only re-confirms what he already builds on rather than challenging or extending anything, and both the finding (one secondary outlet; assistants and operationalization unestablished) and the surrounding typosquat/rogue-MCP coverage (threat environment, not result) leave the claim itself untested — nothing here changes SiloOS or his harnesses, so it stays LOW until replication or consequential pickup turns the receipt into a publishing opening.
ip:framework.architecture-not-vibesip:concept.trust-hierarchyip:framework.falsifiability-spineradar:concept.software-supply-chainradar:concept.dependency-securityradar:safer-dependencies-claude-code-auditingradar:kenwea-npm-install-sandbox
queries asked of Scott's wikis
  • architecture not vibes enforced dependency trust gate install boundary
  • evaluation-driven development pre-registered agent behavior audit
  • coding agent harness install hook package verification check
  • SiloOS dependency installation trust controls sandbox
  • machine-checkable trust signals SBOM signature verification position

Measured heat

now 0 pts/hpeak 18 pts/hcomments 0/hpeers p16momentum: steady3 platformsage 754h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-10 06:23 (minted)⭐ origin echo-reconstructedThe linking HN title states: “AI Coding Assistants Almost Never Check Supply-Chain Trust Signals.”
? on paper (echo) · attributed from hn.story.49639063 · published time unknown
—
09-10 06:07first on hacker news · published · lag ?AI Coding Assistants Almost Never Check Supply-Chain Trust Signals
sbulaev
—
10-05 02:49first on r/ClaudeAI · published · lag ?I built an offline scanner with Claude Code that audits the MCP servers and skills installed on your machine (free, MIT)
Happy-Athlete-2420
—
09-10 06:07amplified on hacker newshn.story.49639063
sbulaev
peak 3 · 0 comments · 8% of case engagement
09-18 19:04amplified on hacker newshn.story.49758756
ibobev
peak 4 · 0 comments · 11% of case engagement
09-19 00:27amplified on hacker news 👑hn.story.49762076
binukajayaweera
peak 4 · 5 comments · 24% of case engagement
09-22 12:56amplified on hacker newshn.story.49800489
lumpa
peak 2 · 0 comments · 5% of case engagement
09-22 12:57amplified on hacker newshn.story.49800503
lumpa
peak 2 · 0 comments · 5% of case engagement
10-02 19:16amplified on hacker newshn.story.49937371
kevinold
peak 3 · 1 comments · 11% of case engagement
3 more amplifiers in ainews.case_chain
09-10 06:21our radar first saw it · lag ?discovery anchor: hn.story.49639063—
pace: p58 vs 519 stories at the 720h mark (now 754h old) — ahead of openai-daybreak-frontline-subsidies (1.1x), behind llama-cpp-hy4-preview-support (1.0x)

Evidence (10) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnAI Coding Assistants Almost Never Check Supply-Chain Trust Signalssbulaev30
🟧 echo.paper ⭐The linking HN title states: “AI Coding Assistants Almost Never Check Supply-Chain Trust Signals.”——
🟧 hnNot in My Git Yard: Catching Backdoors at Commit and Release Timeibobev40
🟧 hnShow HN: An OSS Python dependency scanner for exploited, unmaintained packagesbinukajayaweera45
🟧 hnUnfinished Work in Package Securitylumpa20
🟧 hnPackage Manager Threat Model, Revisitedlumpa20
🟧 hnMaintaining wait-on at agent speed: AI, NPM supply-chain risk, and a Rust enginekevinold31
🟠 redditI built an offline scanner with Claude Code that audits the MCP servers and skills installed on your machine (free, MIT)
ClaudeAI
Happy-Athlete-242027
🟧 hnSecret protection must scale with software: <2ms classifier in the push pathhavens60
🟧 hnFakeGit malware campaign returns with 17,610 malicious GitHub reposshmulc20

Interpretation history

Decision trace