For decades, open-source software carried an implicit signal of trust. A person who spent years building, maintaining, documenting, and supporting a project had invested something difficult to fake: time. That investment did not guarantee good intent, but it made sustained deception expensive.
AI agents change that equation. Software that once required years of skilled work can increasingly be produced in days. Soon, a convincing library, developer tool, or infrastructure project may require little more than a capable model, a plausible identity, and a bit of patience.
That changes the economics of supply-chain attacks. An attacker no longer needs to infiltrate a trusted project. They can manufacture one, make it genuinely useful, earn adoption, and wait.
Quality, polish, and apparent commitment cease to be reliable proxies for intent. When the cost of creating software approaches zero, the cost of creating credible software approaches zero with it.
Trust can no longer be inferred from effort. It has to be established independently.