The paper is now identified: arXiv:2609.07754, 'Do AI Coding Assistants Check Before They Install? A Pre-Registered Demand-Side Audit of Trust Signals in the Research Software Supply Chain', authored by Pengyin Shan (submitted 7 Sep 2026, cs.CR), whose bibliography shows prior 2026 work auditing research-software citation metadata and situates the study in a small cluster of agent-security audits (weaponized setup instructions, in-band governance-signal compliance, provenance sensitivity). Secondary coverage (Quantum Zeitgeist) reports the design as 1,920 registered trials in which assistants verified origin trust signals such as SBOMs or signatures in under 1% of trials — consistent with the HN title's 'almost never' — and a LinkedIn post by Skip Sanzeri independently references the testing. What the supplied snippets still do not establish: which assistants were tested, how 'checking' was operationalized, and any independent examination or replication beyond one secondary outlet and one social mention. The surrounding coverage does document the threat environment the paper addresses — a Cloud Security Alliance note on skills-marketplace compromise and SANDWORM_MODE typosquatted npm packages deploying rogue MCP servers, and CSO Online on DPRK-crafted packages and 'slopsquatting' of hallucinated dependencies, with explicit guidance that agents should not install dependencies without developer review.
The grounding upgrade is real: a named author, a pre-registered 1,920-trial design, and a <1% verification headline make this the first quantified dated receipt for the premise of Architecture Not Vibes and Trust Hierarchy — model cooperation is not a control, so install-boundary checks must be enforced — and the pre-registration itself speaks Scott's Falsifiability Spine. But it only re-confirms what he already builds on rather than challenging or extending anything, and both the finding (one secondary outlet; assistants and operationalization unestablished) and the surrounding typosquat/rogue-MCP coverage (threat environment, not result) leave the claim itself untested — nothing here changes SiloOS or his harnesses, so it stays LOW until replication or consequential pickup turns the receipt into a publishing opening.
ip:framework.architecture-not-vibesip:concept.trust-hierarchyip:framework.falsifiability-spineradar:concept.software-supply-chainradar:concept.dependency-securityradar:safer-dependencies-claude-code-auditingradar:kenwea-npm-install-sandbox
queries asked of Scott's wikis
- architecture not vibes enforced dependency trust gate install boundary
- evaluation-driven development pre-registered agent behavior audit
- coding agent harness install hook package verification check
- SiloOS dependency installation trust controls sandbox
- machine-checkable trust signals SBOM signature verification position
now 0 pts/hpeak 18 pts/hcomments 0/hpeers p16momentum: steady3 platformsage 754h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
2026-10-09T03:56:50Z
Two new attachments (Copilot push-path secret classifier; FakeGit 17.6k-repo malware campaign) corroborate the threat environment the paper addresses, but neither examines the paper's specific <1% verification finding — the claim still rests on one secondary outlet (Quantum Zeitgeist) and one LinkedIn mention with no independent replication, methods detail, or author confirmation after ~29 days. Measured heat is near-zero (0.33 pts/h) despite hot coding-agents/agentic-security neighborhoods; the 67th peer percentile reflects cohort noise, not signal. Mitigation tooling continues accumulating (Python scanner, SecureAI-Scan) but validates neither the claim nor its own reliability. Case remains an unverified receipt illustrating Scott's frameworks without challenging them.
2026-10-08T23:06:44Z
evidence attached: hn.story.50011196 — Large-scale FakeGit malware campaign on GitHub is a concrete instance of the supply-chain trust failures the case tracks.
2026-10-08T23:06:43Z
evidence attached: hn.story.50007593 — GitHub Copilot's push-path secret classifier relates to supply-chain trust signals for coding assistants.
2026-10-05T03:46:55Z
grounded: converges/low — The grounding upgrade is real: a named author, a pre-registered 1,920-trial design, and a <1% verification headline make this the first quantified dated receipt
2026-10-05T03:38:47Z
A second independent mitigation artifact (offline MCP/skills auditor) presupposes the trust gap but, like the Python scanner and every prior attachment, tests nothing about the paper's actual finding — the case is drifting from a specific unverified arXiv claim toward an index of agent-trust tooling that already has homes in the adjacent coding-agent-security cases; heat stays low and nothing here earns corroboration of the claim itself.
2026-10-05T03:24:00Z
evidence attached: reddit.post.1wxxnwu — Released offline scanner auditing installed MCP servers, skills, and plugins for unpinned/malicious packages and poisoned instructions is concrete tooling emerging to close exactly the documented trust-signal gap.
2026-10-02T19:57:37Z
The wait-on maintainer's first-person account adds a genuine practitioner voice to the surrounding agent-speed/NPM-risk narrative but, like every prior attachment, never touches the paper's actual finding — the case has settled into an unverified single-source claim ringed by recurring but non-testifying practitioner concern. Thin adjacent coverage shouldn't keep re-warming this; heat stays low until something independently checks the study or validates the scanner hook.
2026-10-02T19:29:58Z
evidence attached: hn.story.49937371 — First-person maintainer account of agent-speed PR volume and NPM dependency-trust risk materially contextualises the supply-chain-trust case with real-world maintenance evidence.
2026-09-23T18:04:36Z
The two newly attached package-security titles add topical context, but no findings that corroborate coding assistants' alleged neglect of trust signals or validate the reported install hook. The case remains an unverified research claim with a candidate mitigation, not a demonstrated reason to change Scott's coding-agent controls.
2026-09-22T13:23:24Z
evidence attached: hn.story.49800489 — Its revisited package-manager threat model bears directly on supply-chain trust assumptions relevant to coding-agent execution.
2026-09-22T13:23:24Z
evidence attached: hn.story.49800503 — This package-security analysis materially contextualizes the unresolved need for stronger dependency and package trust controls in coding-agent workflows.
2026-09-19T01:22:03Z
A scanner author's report of a Claude install hook adds a concrete candidate for enforcing dependency-trust checks, moving the case beyond a purely hypothetical mitigation. It does not corroborate the study's claimed assistant failure rate or establish that the hook reliably blocks risky installations.
2026-09-19T01:21:24Z
evidence attached: hn.story.49762076 — The released scanner is a concrete implementation of explicit dependency-trust checks for coding agents, directly bearing on the open supply-chain-trust hypothesis.
2026-09-18T19:59:17Z
The newly attached backdoor-detection title is adjacent supply-chain research, not corroboration that coding assistants neglect dependency-trust signals. It supplies no findings or implementation results that strengthen the original claim or justify changing Scott’s controls.
2026-09-18T19:22:26Z
evidence attached: hn.story.49758756 — The paper's focus on detecting backdoors at commit and release time directly bears on supply-chain verification for AI-assisted software development.
2026-09-10T06:33:05Z
The title and its reconstructed echo remain a single unverified line of evidence, with no new methods, findings, or workflow implications established. This remains a candidate dependency-trust evaluation question, not evidence that Scott should change his coding-agent controls.
2026-09-10T06:25:58Z
grounded: converges/low — The reported claim directionally converges with Scott’s Architecture, Not Vibes and Evaluation-Driven Development positions: dependency-trust checks would belon
2026-09-10T06:23:13Z
case created — A linked research paper supplies a bounded security claim distinct from existing supply-chain and agent-permission cases, although its methods and scope are not visible here.