It seems the arrival of super-intelligent open source models necessitates now that all software undergo pen-testing from an AI agent. Otherwise the program will be doomed to exploits from blackhat AI agents. This should be required all the way up the dependency chain for all software systems.

Historically users of open source software have mostly relied on the "wisdom of the masses" to determine sufficient security. Since AI agents have recently found many vulnerabilities among some of the world's most popular repositories, diligence must improve. Open source repositories will need to provide verifiable proof that they have undergone pen-testing by a sufficiently capable AI agent.

We are quickly entering the era of cyber-warfare among non-human intelligence. Up to now this front's situation has been academically interesting. Now it is practically necessary to pay attention and act.