VibeCoded

AI coding agents are pulling packages nobody registered

September 8, 2026. From issue 5 of The Compliance Brief, one story for founders shipping AI-built and vibe coded apps.

Last reviewed 2026-09-08Written by Jacob Masse, TrazTech Inc.

Issue 5 of The Compliance Brief was published on September 8, 2026. One of its 5 stories bears on AI security, LLM attacks and app security flaws, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Schneier on Security

Researchers scanned 6,214 live domains belonging to defence contractors, Fortune 500 and large tech companies and found 8,265 llms.txt and llms-full.txt files. Of those, 120 on different sites pointed to code packages or domain names that were not registered.

Our take, in short

This is dependency confusion with a new delivery path, and the old defences still apply. Pin your dependencies, keep an internal registry that fails closed on unknown names, and make sure an agent cannot install anything that a human would not have been allowed to install.

Read the full take on traztech.ca

Also in issue 5

Outside AI security, LLM attacks and app security flaws, but in the same email:

Older: issue 4 All issues on VibeCoded Newer: issue 7