##### Press release

# New Research from UpGuard: 1 in 5 Developers Grant AI Vibe Coding Tools Unrestricted Workstation Access

##### [UpGuard Team](#)

February 4, 2026

### *Widespread "YOLO Mode" risks in AI coding tools are creating significant supply chain and data breach exposure*

**Mountain View, CA - February 4, 2026** - [UpGuard](https://www.upguard.com/), a leader in cybersecurity and risk management, released new research highlighting a critical security vulnerability within developer workflows. UpGuard’s analysis of more than 18,000 AI agent configuration files from public GitHub repositories identified a concerning pattern: one in five developers have granted AI code agents unrestricted access to perform high-risk actions without human oversight.

In using AI to improve efficiency, developers are granting extensive permissions to download content from the web, and read, write, and delete files on their machines without requiring developer permission. This comes at the cost of essential security guardrails, exposing organizations to major supply chain and data security risks.

"Security teams lack visibility into what AI agents are touching, exposing, or leaking when developers grant vibe coding tools broad access without oversight," said Greg Pollock, director of Research and Insights at UpGuard. “Despite the best intentions, developers are increasing the potential for security vulnerabilities and exploitation. This is how small workflow shortcuts can escalate into major supply chain and credential exposure problems."

‍

**Key Findings:**

* **Widespread Potential for Damage:** 1 in 5 developers granted AI agents the permission for unrestricted file deletion, allowing a small error or prompt injection attack to recursively wipe a project or system.
* **Risk from Unchecked AI Development:** Almost 20% of developers let the AI automatically save changes to the project's main code repository, skipping a necessary human review. This automated setup creates a serious security gap, as it allows an attacker to easily insert harmful or malicious code directly into the production system or open-source projects, which could lead to widespread security compromises.
* **High-Risk Execution Permissions:&#x20;**&#x41; significant number of files granted permissions for arbitrary code execution, including 14.5% for Python and 14.4% for Node.js, effectively giving an attacker full control over the developer's environment through a successful prompt injection.
* **MCP Typosquatting Threat:&#x20;**&#x41;nalysis of the Model Context Protocol (MCP) ecosystem revealed extensive use of lookalike servers, creating ripe conditions for attackers to impersonate trusted technology brands. In the registries where users look for these AI tools, for every server provided by a verified technology vendor there were up to 15 lookalikes from untrusted sources. 

‍

These risks highlight a critical governance gap, slowing down incident response and increasing the likelihood of credential and data exposure. To read UpGuard’s recent research on vibe coding, visit the following:

* YOLO Mode: Hidden Risks in AI Coding Agents: <https://hubs.li/Q041Cb0H0> 
* Emerging Risks: Typosquatting in the MCP Ecosystem: <https://hubs.li/Q041CCpq0> 

‍

**About UpGuard’s Breach Risk&#xA0;**

UpGuard's Breach Risk solution is designed to turn hidden shortcuts such as misconfigurations or overly broad permissions to early threat signals like dark web chatter, into clear, actionable visibility. By providing deep insight into the AI-generated changes, access, and data flow, UpGuard’s Breach Risk solution helps security teams enforce a strict governance framework.

‍

**About UpGuard**

Founded in 2012, [UpGuard](https://www.upguard.com/) is a leader in cybersecurity and risk management. The company's AI-powered platform for cyber risk posture management (CRPM), provides a centralized, actionable view of cyber risk across an organization's vendors, attack surface, and workforce. Trusted by thousands of companies, UpGuard's platform is designed to help security teams manage cyber risk with confidence and efficiency. To learn more, visit www\.upguard.com.

**MEDIA CONTACT**

Julie Huang

<press@upguard.com>

### Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.

## UpGuard blog

Learn about the latest issues in cybersecurity.

#### [Find Out if You're Exposed on the Dark Web](/blog/find-out-if-youre-exposed-on-the-dark-web)

Answer 5 quick questions to predict what a dark web scan will find about your company. Then run the free scan to see your real exposure.

[](/team/lance-turner)

[Lance Turner](#)

September 28, 2026

#### [The Evidence Is In: UpGuard Named a Leader in the IDC MarketScape for Worldwide Third-Party Risk Management](/blog/upguard-named-leader-in-idc-marketscape)

UpGuard has been named a Leader in the IDC MarketScape: Worldwide Third-Party Risk Management Services 2026 Vendor Assessment. Find out why.

[](/team/cassy-van-eeden)

[Cassy van Eeden](#)

September 22, 2026

#### [Your First Dark Web Scan Report, Explained](/blog/your-first-dark-web-scan-report-explained)

You scanned your domain. What do the results mean?

[](/team/lance-turner)

[Lance Turner](#)

September 21, 2026

#### [We Researched Four AI Evidence Analysis Tools for TPRM. Here’s What We Found.](/blog/ai-evidence-analysis-tools-for-tprm)

We researched four AI evidence-parsing tools against four criteria that security teams often overlook. None nailed all four.

[](/team/cassy-van-eeden)

[Cassy van Eeden](#)

September 29, 2026

#### [12 Cybersecurity Horror Stories of 2026 (No Costume Required)](/blog/cybersecurity-horror-stories-2026)

A warning ignored once becomes a headline. Read more about these 12 real 2026 cybersecurity incidents, and the sign each one gave before it made the news.

[](/team/revashni-moodley)

[Revashni Moodley](#)

September 28, 2026

#### [Good Security Rating? Your Dark Web Exposure Says Otherwise](/blog/good-security-rating-your-dark-web-exposure-says-otherwise)

Scan your domain to see just how exposed you are on the Dark Web.

[](/team/lance-turner)

[Lance Turner](#)

September 14, 2026

[View all blog posts](/blog)

## See UpGuard In Action

Book a free, personalized onboarding call with one of our cybersecurity experts.

[Contact sales](/demo)

[Free demo](/demo)

##### Free instant security score

## How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.

* Instant insights you can act on immediately
* Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

[Free score](/instant-security-score)
