AI agent recommends malware package to engineer; code review policy prevents installation
An engineer at Softjourn nearly installed a malicious package recommended by an AI agent, but company policy requiring verification on GitHub prevented the installation. Separately, security researche…