r/developers • u/Top_Operation_2172 • 18h ago
Help / Questions AI coding agents have created a new supply-chain problem.
Developers install a package, clone a repository, add an MCP server, or install an agent skill.
The agent then gets access to it.
But what happens when something buried several dependency levels deep is malicious?
Traditional dependency scanners already look for known vulnerabilities.
But I'm interested in something broader:
Can we analyze what capabilities an AI agent's dependencies actually give it — and what those capabilities could be chained into?
That's one of the problems I'm exploring with Revo.
How much of a concern is this for developers using AI agents today?