Coding Agents Installing Unowned Code: A Security Nightmare
GaryMarcus · x · 2026-09-01
Gary Marcus highlights a critical security issue where AI coding agents like Claude, Codex, and Hermes are installing unowned code within corporate networks. He argues this is potentially much more serious than the OpenAI-Hugging Face incident but receives less attention due to the lack of dramatic narrative. Citing Heidy Khlaaf and his own Substack collaboration with Nathan Hamiel, Marcus reinforces the risks of combining LLMs with coding.
More from Safety
- Polymarket: 69% Chance Any State Enacts Data Center Moratorium by 2026 — Polymarket · 2026-09-01
- METR + Redwood GPT agent swarm probe could only analyze GPT variants, not Claude — geoffreyirving · 2026-09-01
- Man used robot vacuum to record wife's affair, won divorce but jailed for illegal recording — jonerp · 2026-09-01
- AI Agent Optimization Pressure May Exceed Goodhart's Law — dhadfieldmenell · 2026-09-01
- Scholar asks editors to allow LLM assistance for peer review, gets rejected — RexDouglass · 2026-09-01
- Instagram Admits Users Can't Distinguish AI Profiles from Humans — The Decoder · 2026-09-01