Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Snyk: AI Code Assistant Runs Its Own Security Audit

Snyk
07/05/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


It's on the last step of its to-do list for this prompt. I noticed it's running its own audit. I'm using PMPM on this machine. It ran PMPM audit, and that's giving it a little bit of an advantage in the sense that it's going to read the security results for open source dependencies that PMPM provides to it. And so now what it's trying to do is address those. And I think that kind of gives it a little bit of an unfair advantage, but the fact that it knew to do that is also a nice thing. On the other hand, it'd be great if the model just chose open source dependencies that didn't have vulnerabilities in them in the first place, so that it would not have to go through this iteration of finding and fixing vulnerabilities in those dependencies.

TL;DR

  • An AI code assistant autonomously ran a pnpm security audit mid-task, demonstrating proactive security awareness without being explicitly instructed to do so.
  • The model read the audit results and attempted to fix vulnerable open-source dependencies, adding a self-directed remediation step to its workflow.
  • The presenter argues the ideal outcome would be for AI models to select vulnerability-free dependencies upfront, eliminating the need for iterative find-and-fix cycles.

Summary

This short clip captures a live observation of an AI code assistant — running inside the Cursor IDE — autonomously executing a package manager security audit (pnpm audit) as part of its own workflow. The presenter notes that the model proactively ran the audit to read open-source dependency vulnerability results and then attempted to remediate the flagged issues. While this self-directed security awareness is framed as a positive signal — demonstrating that AI agents can recognize and act on security signals without being explicitly prompted — the presenter also raises a more fundamental concern: ideally, the AI model would select secure open-source dependencies from the outset, avoiding the need for a find-and-fix iteration loop altogether. The clip is an excerpt from a longer video exploring AI code security practices, and highlights the evolving capability — and current limitations — of AI-assisted development when it comes to dependency security.

Chapters

0:00 - Task Nearing Completion
0:05 - AI Runs Its Own Audit
0:20 - Addressing Vulnerabilities
0:30 - The Ideal: Secure Dependencies Upfront

Key Quotes

0:05 "I noticed it's running its own audit."
0:11 "... that's giving it a little bit of an advantage in the sense that it's going to read the security results for open source dependencies that PMPM provides to it."
0:30 "... it'd be great if the model just chose open source dependencies that didn't have vulnerabilities in them in the first place, so that it would not have to go through this iteration of finding and fixing vulnerabilities in those dependencies."

FAQ

What did the AI code assistant do that was notable in this clip?

Without being explicitly prompted, the AI assistant ran a pnpm audit to check open-source dependencies for known vulnerabilities, then attempted to address the issues it found — all as part of completing its assigned task.

Why does the presenter call this an 'unfair advantage'?

Because the AI leveraged the pnpm audit tool's security output to inform its decisions, giving it access to vulnerability data that a developer might not have manually checked — though the presenter also sees this as a positive capability.


Categories:
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Application Security
  • DevSecOps
  • Demo
  • Getting Started
  • AI code assistants
  • Open-source dependency security
  • Automated security auditing
  • pnpm audit
  • AI-assisted development
  • Vulnerability remediation
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Snyk: AI Code Assistant Runs Its Own Security Audit

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Ensuring Compliance Through Audit Evidence: From CJIS to FERPA

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Ensuring Compliance Through Audit Evidence: From CJIS to FERPA
                      https://www.truthinit.com/index.php/channel/2159/ensuring-compliance-through-audit-evidence-from-cjis-to-ferpa/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version