AgentsAugust 27, 2026via Ars Technica
Claude, Codex, and Hermes installed unowned code inside corporate networks
Why it matters
AI agents and code-generation tools are autonomously installing dependencies and packages that have no maintainer — a supply-chain and security risk that bypasses human code review. This is a live deployment failure mode for agentic development workflows.
Key signals
- 227 install commands found in corporate documentation pointing to unowned code
- Three models flagged: Claude, Codex, Hermes
- Code was installed inside corporate networks
- Suggests autonomous code generation without human review or dependency validation
- Supply-chain security risk at the agent/autonomous-workflow layer
The hook
227 install commands. AI models auto-generating code that nobody owns, deployed inside corporate networks right now.
227 install commands were found in corporate docs pointing at code nobody owns.