Coding Agents Installing Unowned Code: A Security Nightmare

GaryMarcus · x · 2026-09-01

Gary Marcus highlights a critical security issue where AI coding agents like Claude, Codex, and Hermes are installing unowned code within corporate networks. He argues this is potentially much more serious than the OpenAI-Hugging Face incident but receives less attention due to the lack of dramatic narrative. Citing Heidy Khlaaf and his own Substack collaboration with Nathan Hamiel, Marcus reinforces the risks of combining LLMs with coding.

Related event: Warning: AI Coding Agents Installing Unauthorized Code in Enterprise Networks(2 posts)→

Original post →

More from Safety

Safety channel →