Agentic Security: Permissions, Provenance, and the Agent Supply Chain — Steve Yegge, Gas Town
AI-accelerated coding multiplies security vulnerability surface by 10x or worse
“if everyone's shipping code at 10 times faster and the defect rate stays the same, the vulnerability rate then that doesn't that mean that the defect surface goes up by 10x?”
Steve Yegge argues that AI-assisted development creates a compounding security crisis: 10x coding velocity means 10x more vulnerabilities shipped, and AI-generated code likely has a worse defect rate than human-written code, not the same. Beyond scaling classic bugs like XSS, he flags entirely new vulnerability classes emerging from agentic systems and the agent supply chain.