The Pipeline Mag Podcast

AI Coding Assistants Skip the Labels Before They Install

A pre-registered audit of 1,920 trials by researcher Pengyin Shan finds that AI coding assistants open a provenance signal before installing software only 0.5% of the time, and never once execute a verification command — even when the signature was forged by the wrong issuer. Two hosts trace the study’s design, from the ChainDrop npm worm that needs no command at all to trigger, through to why price bought no more caution from the models tested.

They also weigh the honest complication the audit raises against itself: even flawless verification would not have caught 2026’s worst supply-chain attack, since Mini Shai-Hulud shipped with valid, stolen-credential provenance. The real gap, they argue, isn’t the badge — it’s that nothing in today’s coding-agent harnesses reads it.

This episode was made from the article AI Coding Assistants Skip the Labels Before They Install.