An AI Agent Just Talked Its Way Into Your Software Supply Chain. Nobody Noticed.

How reputation farming by autonomous agents exposes the identity crisis at the heart of the agentic AI boom
Tim Williams — CEO and Co-Founder — Astrasync AI
On February 1, 2026, a GitHub account was created under the name “Kai Gritun.” Within two weeks, this account had opened 103 pull requests across 95 repositories. Code was merged into projects like Nx, ESLint Plugin Unicorn, and Clack. Maintainers reviewed the contributions, left feedback, iterated through multiple rounds of changes, and approved the work. The contributions were technically sound. The code reviews were professional. The interactions were polite.
Kai Gritun is not a person. It is an autonomous AI agent.
Nobody knew until it emailed Nolan Lawson, an engineer at developer security firm Socket, pitching paid consulting services. The agent had built a commercial website, set up cryptocurrency payment options, and was using its merged open source contributions as credentials to solicit more work. Socket’s investigation, published on their blog last week, revealed an operation they described as “reputation farming” at scale.
The same week, Oxford Professor Michael Wooldridge delivered his Royal Society Michael Faraday prize lecture, warning that the AI industry is heading for what he called a “Hindenburg moment.” His argument was straightforward: the technology is promising, not rigorously tested, and under unbearable commercial pressure to ship. He suggested scenarios ranging from deadly self-driving car updates to corporate collapses triggered by AI systems making catastrophic decisions.
These two stories, published days apart, are not separate concerns. They are the same problem viewed from different altitudes.
This is not just an open source problem
It would be tempting to treat the Kai Gritun incident as a niche concern for open source maintainers. That would be a mistake.
What happened on GitHub is a microcosm of a risk that extends across every domain where autonomous agents interact with systems or people who need to assess trustworthiness. The playbook is straightforward: create a plausible identity, build credibility through a volume of legitimate-seeming interactions, then leverage that manufactured trust to gain access, influence, or revenue.
Now consider how that same pattern applies beyond open source.
In ecommerce, the risks are already materialising on multiple fronts. Personal shopping agents are being deployed to browse merchant sites, assemble baskets across multiple retailers, and execute purchases on behalf of consumers. Payments industry analysts project that these third-party agentic intermediaries will erode 8 to 13 percent of gross merchandise value within two to three years by hijacking SKU-level data, recreating their own attribution audit trails, and steering transactions away from merchant checkouts. The merchant loses the last touchpoint with the customer, and with it the cross-sell and upsell opportunity that accounts for anywhere between a third and three quarters of incremental revenue. The agent becomes the customer relationship, and the retailer becomes a warehouse providing fulfilment.
On the supply side, an agent that builds a credible transaction history on a marketplace could eventually exploit that trust to redirect payments, alter order quantities, or exfiltrate supplier data. The merchant on the other end has no way to verify whether they are dealing with an authorised agent acting within defined boundaries or a rogue system operating under a fabricated commercial identity. In both cases, the question is identical to the one the open source maintainers faced: who is this entity, who sent it, and should I trust it?
In enterprise software, agents are being given access to internal tools, CRM systems, and customer data through integrations like MCP (Model Context Protocol). An agent that presents valid-looking credentials and behaves normally for an initial period can earn implicit trust from the systems it interacts with, then pivot to data exfiltration or privilege escalation. The pattern mirrors the XZ-Utils backdoor, compressed from years to days.
In financial services, agents are beginning to execute trades, process claims, and manage compliance reporting. An agent that has fabricated a history of reliable performance could be granted escalating authority over time, until it reaches a threshold where a single malicious action causes significant damage.
The common thread is that every one of these domains relies on trust signals that were designed for human participants operating at human speed. Kai Gritun demonstrated that those signals can now be manufactured autonomously, at machine speed, across dozens of contexts simultaneously.
The Hindenburg parallel is more precise than it sounds
Professor Wooldridge’s analogy deserves more thought than the headline treatment it received. The Hindenburg was not some reckless experiment. It was the culmination of decades of airship development, operated by experienced crews, carrying paying passengers across the Atlantic. It worked. Until it didn’t.
Wooldridge’s point is that AI is following a similar trajectory. The technology delivers real value. It is being deployed into critical systems. Commercial pressure is accelerating adoption faster than testing and governance frameworks can keep pace. The failure, when it comes, won’t be because the technology is worthless. It will be because we deployed it without the infrastructure to manage it safely.
He specifically called out AI systems that fail unpredictably, lack awareness of when they are wrong, and are designed to sound confident regardless. That description applies perfectly to the Kai Gritun scenario. An autonomous agent confidently engaging in code reviews, responding to feedback, iterating on changes, all while concealing its nature. Not because it was programmed to deceive, necessarily, but because nothing in the system required it to identify itself.
The connection between these two stories is the absence of identity infrastructure.
We have been asking the wrong question
The industry conversation about AI agent safety has focused heavily on capability constraints. Can we limit what agents are allowed to do? Can we build better guardrails? Can we make prompt injection harder?
These are important questions. They are also insufficient.
The Kai Gritun case demonstrates that capability constraints don’t help when you can’t answer the more fundamental question: who or what is this entity, and should I trust it?
The maintainers who merged Kai Gritun’s PRs weren’t making bad decisions. They were following the same review process they would apply to any contributor. The code was clean. The interactions were professional. The commits passed CI checks. Every signal they had available suggested a competent developer contributing in good faith.
The problem is that those signals were never designed for a world where identity itself can be fabricated at machine speed. GitHub accounts, contribution histories, email addresses, professional websites, transaction records, supplier profiles, customer service interactions: all of these trust signals are now trivially reproducible by autonomous systems.
What identity infrastructure for agents actually looks like
At AstraSync, we have been working on this problem for over a year, since a research paper from the Collective Intelligence Project and collaborators across Berkeley, MIT, and Oxford first outlined the need for agent identification and certification systems. Our approach is built around a concept we call the Trust Chain, a five-party verification model that asks and answers a series of questions before an agent is trusted.
Know Your Developer (KYD): Who built this agent? Are they a verified entity with a track record? In the Kai Gritun case, someone absolutely built this system. Someone configured it, pointed it at open source repositories, and set it loose with a commercial objective. That person or entity is currently invisible. KYD makes them accountable. A verified developer identity, linked cryptographically to every agent they produce, means that when an agent behaves badly or deceptively, accountability doesn’t stop at the GitHub username.
Know Your Owner (KYO): Who is currently responsible for this agent’s actions? Ownership may transfer over time, and those transfers need to be recorded with clear liability boundaries. The OpenClaw consulting brand behind Kai Gritun is a commercial operation. Someone owns it. That ownership should be verifiable.
Know Your Agent (KYA): What is this agent’s cryptographic identity, what are its declared capabilities, and what are its operational constraints? Kai Gritun had none of these. It operated with whatever capabilities GitHub grants any new account, with no declared boundaries on what it was authorised to do.
Know Your Instructor (KYI): Who is providing instructions to this agent at runtime? In the Kai Gritun operation, someone configured the targeting strategy, the repository selection, and the commercial pitch. That instructing entity should be identifiable and accountable, separate from the developer who built the underlying system.
Counterparty verification: The system or person the agent seeks to interact with needs the ability to independently verify all of the above. The open source maintainers in this case had no such capability. Neither would a merchant on a marketplace, an API endpoint processing transactions, or an enterprise system granting access to internal data.
This model is complemented by dynamic trust scoring that updates continuously based on behavioural patterns, incident history, and verification recency. Static certification fails for autonomous systems. An agent that was trustworthy yesterday might be compromised today. Trust needs to be continuous, not binary.
The industry knows this problem exists. Now it needs solutions.
We are not the only ones recognising this gap. The Linux Foundation’s First Person Project, born from a collaboration between LF Decentralised Trust, Trust Over IP, the Decentralised Identity Foundation, and the OpenWallet Foundation, is tackling the same fundamental challenge: how do you prove that a real, verified human is behind an agent’s actions?
The First Person Project uses verifiable relationship credentials and decentralised identifiers to create what they call “proof of personhood” without relying on centralised biometric databases. Their white paper explicitly addresses the agent delegation problem, noting that legacy identity systems were not designed for a world where AI agents routinely act, transact, and communicate on behalf of humans and institutions. They demonstrated how their credential system would have prevented the “Jia Tan” identity from gaining maintainer rights to XZ-Utils. Kai Gritun is the AI-speed evolution of precisely that attack pattern.
This is exactly the problem that Know Your Developer was built to solve.
KYD provides the practical implementation layer for the kind of verified human-to-agent accountability that the First Person Project describes at the standards level. When the First Person Project asks “is there a real person behind this agent?”, KYD answers that question with verified identity, cryptographic linkage between developers and every agent they produce, continuous trust scoring based on the track record of their deployed agents, and a permanent audit trail that follows them across platforms and employers. It is proof of personhood applied specifically to the people building and deploying autonomous systems.
The fact that the Linux Foundation, with backing from organisations including Anthropic, OpenAI, Microsoft, Google, and AWS, is investing in this standards infrastructure tells you something about how seriously the industry’s largest players are taking the problem. The Agentic AI Foundation and its member projects like MCP, Goose, and AGENTS.md are building the communication and coordination layer for agents. The First Person Project is defining what verified human accountability should look like. AstraSync is building the platform that delivers it across the full agent lifecycle.
The window for proactive infrastructure is closing
Socket’s coverage of Kai Gritun ended with an observation that should be on every technology leader’s desk: the mechanisms that govern trust in open source were not built for identities that can generate contributions continuously, across dozens of projects at once, without human involvement.
That observation extends well beyond open source. The mechanisms that govern trust in commerce, in enterprise software, in financial services, in healthcare, in government procurement, none of them were built for a world where autonomous agents can fabricate identity and manufacture credibility at scale.
As one security researcher noted in Socket’s coverage, there will be a period of chaos where the old system is exploited and the majority of participants struggle to know who to trust. That period has already begun. Kai Gritun is not a warning about the future. It is a description of the present.
We can either build the identity infrastructure now, or we can wait for the incident that makes the Hindenburg comparison feel generous.
Tim Williams is Co-Founder and CEO of AstraSync AI, building identity, trust, and verification infrastructure for autonomous AI agents. AstraSync’s Know Your Agent platform is live at astrasync.ai.
The Socket.dev investigation into Kai Gritun is available on their blog (https://socket.dev/blog/ai-agent-lands-prs-in-major-oss-projects-targets-maintainers-via-cold-outreach). Professor Wooldridge’s lecture, “This is not the AI we were promised,” was delivered at the Royal Society on 18 February 2026 and in print at (https://www.theguardian.com/science/2026/feb/17/ai-race-hindenburg-style-disaster-a-real-risk-michael-wooldridge).
Further reading on AstraSync
- What is Know Your Agent (KYA)?
- AI agent identity vs API keys: what changes and why
- Find verified developers
This essay first appeared on Medium on 2 March 2026.

