
Hallucinated package names are an attack surface, and self-hosting is the only option for many teams.
“Three common issues are: the source cannot leave the network, the assistant occasionally invents package names that introduce supply-chain risk, and there is no audit trail when a generated change ships a defect.”
Tanya Lenz
“The important design choice is that the model is not the control plane. The model proposes code, but policy enforcement, dependency verification, source traceability, and outcome measurement live outside the model in systems that engineering teams already trust.”
Tanya Lenz
“The model invents a plausible-looking package name, an attacker registers that name in a public registry, and the hallucinated dependency ships real malware to anyone who installs the suggestion.”
Tanya Lenz
“Do not use this trailer as a blame mechanism. Its job is measurement. The useful question is not whether a particular developer used AI, but whether AI-assisted changes have a different review latency, rollback rate, or defect escape rate than the baseline.”
Tanya Lenz
“The acceptance rate is not enough. It conflates trivial completions with meaningful engineering work. The metrics that matter are defect escape rate, rollback frequency, review latency, and incident count, broken out by AI-assisted versus baseline.”
Tanya Lenz
articleHow to Use AI Agents to Prepare 3D Scenes for Simulation
articleTranslating CUDA Tile Operations from Python to Rust Using Agentic AI
articleHow NVIDIA Groq 3 LPX Deterministic Execution Drives Power-Efficient High-Interactivity Inference on NVIDIA Vera Rubin
articleAccelerating Dropless MoE Training in JAX with NVIDIA Transformer EngineChecking sign-in…
Loading comments…