AI Coding Tools Drive Security Gaps In Supply Chains

AI Coding Tools Drive Security Gaps In Supply Chains

As AI development accelerates, enterprises are being flooded with code suggestions that introduce vulnerabilities, expose sensitive APIs, and expand attack surfaces faster than governance can keep up. A new study by Endor Labs highlights how deeply these risks are already embedded in day-to-day development. Only a fraction of dependency versions recommended by AI coding assistants are safe for production use, according to Endor Labs’ State of Dependency Management 2025: Security in the AI-Code Era. 

The findings highlight how the rise of agentic coding tools and the rapid spread of Model Context Protocol (MCP) servers are reshaping software supply-chain risk, not gradually, but at enterprise scale today.

AI-Generated Code Is Flooding Projects With Known Risks

The report shows that only one in five AI-suggested dependency versions were free of hallucinated packages or known vulnerabilities. Depending on the AI model, 44% to 49% of imported dependencies contained publicly documented security issues, a trend that mirrors what recent supply-chain security research has found across widely used package ecosystems.

This surge in unvetted imports is being compounded by the rapid adoption of MCP servers, which link AI agents to thousands of external tools. While MCP unlocks valuable automation, it also centralizes access points where malicious or accidental code changes can slip into production systems. Security teams now face an attack surface that grows automatically as coding agents interact with more services.

Henrik Plate, a security researcher at Endor Labs, warns that developers are being handed dependencies that appear functional but may not have undergone any substantive security review. “Thousands of third-party MCP servers are being developed and published,” he notes. “Without sufficient verification, they could open new paths for exploitation.”

Safeguards Help But Can’t Replace Oversight

Endor Labs’ analysis also shows where progress is possible. When AI agents were equipped with embedded security tools, such as vulnerability scanners or policy checks, the share of safe dependency suggestions jumped from about 20% to 57%. That nearly threefold improvement demonstrates that automated guardrails can materially reduce risk.

But the broader ecosystem still shows signs of structural fragility. In under a year, more than 10,000 MCP servers were published, 40% of them without a license and roughly three-quarters built by individuals rather than organizations with established security practices. Compounding the issue, 82% connect directly to sensitive APIs. Trade reports have noted similar patterns in other fast-moving open-source environments, where speed of release often outweighs hardening and review.

Why Governance Must Move Closer to the Code

One emerging consideration is how quickly governance models themselves will need to evolve as agentic tools become embedded in everyday development. In recent years, incidents tied to compromised open-source libraries, such as the “event-stream” and “ua-parser-js” compromises, showed how quietly a dependency can infiltrate major applications before detection. AI-driven tooling accelerates that dynamic, meaning safeguards can no longer sit at the perimeter of the pipeline. The organizations making the safest transition will likely be those that treat dependency verification as a first-class development capability, with automated controls positioned as close as possible to where code is generated and selected.

Subscribe to Newsletter

Don’t miss tomorrow’s supply chain industry news

Let Supply Chain 360’s free newsletter keep you informed, straight from your inbox.

Tip: select one or more digests.

EVENTS

03 MAR
LIVE EVENT | The Belfry, Birmingham, UK

SupplyChain360 Summit

3rd & 4th March 2027
06 OCT
LIVE EVENT | Soho Hotel London

SupplyChain360 Forum

6th October 2026