AI Supply Chain Security: Artifact Detection and Broader Threats
Blacklight toolkit detects artifacts from AI coding agents (Codex, Claude Code, Cursor). A new taxonomy maps 7 AI supply-chain attack types and 8 controls, referencing real incidents (LiteLLM, PyTorch). Recent empirical study on LLM security across frameworks shows no universal winner; cost does not correlate with security. The k8s-aibom controller generates runtime ML-BOMs with confidence flags. A practical guide on release gates for AI-generated code provides risk classification and test validation. This is a developing area for organizations adopting AI-assisted development.
Sources (3)
Updated Aug 19, 2026