BS Summary: This article contains 30 faulty reasoning types, including Indoctrination, Biased Writer Voice, and Hasty Generalization, with Appeal to Authority as the most egregious example at 28.5% saturation with 177 hits. Analysis detected 1,780 faulty-reasoning hits from 621 analyzed words, generating a BS Score of 58.3% and a BS Rank of 64% (8,020 of 21,886 articles). This article is worse (more manipulative) than 63.40% of the article peer group.

Software supply chain security was hard enough. 
Then AI joined the build pipeline. 
For five years, "software supply chain security" meant one question: what's in your code? 
Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? 
SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk lives less in the code a team writes and more in everything that produces it. 
Shai-Hulud, the self-propagating malicious package campaign that spread through developer toolchains this year, taught the next one: knowing what's in your code is still necessary, but it's no longer sufficient. 
In the roughly 20 months since the Model Context Protocol launched, AI tools, models, and the infrastructure around them have become load-bearing parts of how software gets built, deployed, and run. 
Code is written by agents. 
Packages are pulled in by autonomous tools that decide they are needed. 
Prompts have become a real input to the build, which means they're a real way to compromise it. 
None of this was in scope when most security programs were designed. 
Where the risk actually moved 
It's tempting to treat AI-generated code as just more code, run it through the same scanners, and call it covered. 
That misreads where the risk moved. 
The provenance question that has always defined supply chain security - where did this come from and can I trust it - now applies to the model, the agent, and the tooling, not only the artifact. 
An AI coding assistant suggests a dependency and a developer accepts it without the package ever crossing a human's threat model. 
An autonomous agent reaches for a tool over MCP to complete a task, and that tool reaches for another. 
A prompt, crafted by an attacker and planted somewhere the model will read it, steers what gets written or what gets pulled in. 
Validating AI-generated code before it's committed is table stakes. 
The harder problem is governing the agents doing the writing and the tools they call. 
What a program looks like when AI is in scope 
The teams we work with aren't short on findings. 
They're drowning in them. 
Adding "scan the AI output too" to an already overloaded queue makes the alert pile taller, not the program stronger. 
Two things change when AI is genuinely in scope. 
First, lineage has to extend to everything entering the pipeline, including the models and agents.One approach is extending lineage to the pipeline itself - tracing activity, provenance, and configuration changes from first commit to runtime, and applying the same rigor to models and agents as to any other dependency. 
Second, prioritization has to be based on real exploitability, not volume. 
Correlating findings with runtime context with what's actually reachable is the difference between a vulnerability list and a workable chain of exploit. 
That difference matters more, not less, once an agent can generate a thousand lines of plausible code before lunch. 
This is the gap that Gartner formalized in June when it published the inaugural Magic Quadrant for Software Supply Chain Security - the market's acknowledgment that a problem teams have been defending without a budget line is now something worth evaluating systematically. 
On July 22, OX researchers are hosting a webinar - How AI Is Reshaping Supply Chain Security As We Know It - to walk through new research alongside security leaders doing this work from the inside. 
We'll cover how AI integration changed the attack surface, findings from the first systematic look at MCP servers in the wild, and what a supply chain security program actually looks like when AI is in scope rather than bolted on after. 
Register here. 
Bring hard questions. 
Article reasoning-pattern comparisonThis article: 4.2%The Hacker News: 1.8%The Hacker News: 1.9%Confirmation Bias4.2%This article: 9.5%The Hacker News: 0.8%The Hacker News: 1.2%Anchoring Bias9.5%This article: 14.0%The Hacker News: 3.5%The Hacker News: 3.3%Availability Heuristic14.0%This article: 5.3%The Hacker News: 1.5%The Hacker News: 1.5%Representativeness Heuristic5.3%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.6%Hindsight Bias0.0%This article: 9.8%The Hacker News: 2.7%The Hacker News: 2.5%Overconfidence Bias9.8%This article: 4.8%The Hacker News: 2.8%The Hacker News: 2.7%Framing Effect4.8%This article: 7.9%The Hacker News: 1.3%The Hacker News: 1.0%Loss Aversion7.9%This article: 1.9%The Hacker News: 0.6%The Hacker News: 0.6%Status Quo Bias1.9%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 5.0%The Hacker News: 1.4%The Hacker News: 1.3%Optimism Bias5.0%This article: 3.2%The Hacker News: 1.4%The Hacker News: 1.6%Pessimism Bias3.2%This article: 15.5%The Hacker News: 6.6%The Hacker News: 6.7%Negativity Bias15.5%This article: 0.0%The Hacker News: 1.5%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 3.4%The Hacker News: 0.3%The Hacker News: 0.4%Fundamental Attribution Error3.4%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%The Hacker News: 0.8%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 10.8%The Hacker News: 1.0%The Hacker News: 1.5%Recency Bias10.8%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Ad Hominem0.0%This article: 3.2%The Hacker News: 0.2%The Hacker News: 0.1%Straw Man3.2%This article: 28.5%The Hacker News: 3.7%The Hacker News: 4.0%Appeal to Authority28.5%This article: 21.6%The Hacker News: 2.4%The Hacker News: 1.6%False Dilemma21.6%This article: 3.1%The Hacker News: 0.4%The Hacker News: 0.5%Slippery Slope3.1%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 22.4%The Hacker News: 5.1%The Hacker News: 4.3%Hasty Generalization22.4%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Red Herring0.0%This article: 6.8%The Hacker News: 0.3%The Hacker News: 0.2%Bandwagon6.8%This article: 3.7%The Hacker News: 1.3%The Hacker News: 1.1%Appeal to Emotion3.7%This article: 5.6%The Hacker News: 0.9%The Hacker News: 0.5%Begging the Question5.6%This article: 5.8%The Hacker News: 1.8%The Hacker News: 1.9%Post Hoc (False Cause)5.8%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%The Hacker News: 0.4%The Hacker News: 0.6%Burden of Proof0.0%This article: 2.4%The Hacker News: 0.2%The Hacker News: 0.1%Appeal to Nature2.4%This article: 7.9%The Hacker News: 0.5%The Hacker News: 0.3%Composition/Division7.9%This article: 4.0%The Hacker News: 1.2%The Hacker News: 1.0%Anecdotal4.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 7.2%The Hacker News: 1.3%The Hacker News: 2.3%Ambiguity (Equivocation)7.2%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 1.4%The Hacker News: 0.8%The Hacker News: 1.4%Unattributed Quote1.4%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 23.2%The Hacker News: 1.9%The Hacker News: 2.3%Biased Writer Voice23.2%This article: 23.5%The Hacker News: 5.0%The Hacker News: 4.4%Indoctrination23.5%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 20.9%The Hacker News: 6.7%The Hacker News: 3.0%Attempt to Sell a Product or S…20.9%

621 words analyzed.

Speakers

2speakers13%attributed speech543writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 12 words • 100.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 6 words • 100.0% coverageWriter's voice • 14 words • 100.0% coverageWriter's voice • 16 words • 100.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 30 words • 100.0% coverageWriter's voice • 31 words • 100.0% coverageWriter's voice • 5 words • 100.0% coverageWriter's voice • 12 words • 100.0% coverageWriter's voice • 18 words • 100.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 20 words • 100.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 36 words • 100.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 23 words • 100.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 9 words • 100.0% coverageWriter's voice • 4 words • 100.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 9 words • 100.0% coverageWriter's voice • 49 words • 100.0% coverageWriter's voice • 11 words • 100.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageGartner • 42 words • 100.0% coverageOX researchers • 36 words • 100.0% coverageWriter's voice • 41 words • 100.0% coverageWriter's voice • 2 words • 100.0% coverageWriter's voice • 3 words • 100.0% coverage
Selected voice

Gartner

100%flagged-word coverage
42 attributed words54% of attributed speech97% writer coverage
0%50.0%100.0%Attempt to Sell a Product +90.4 ptsWriter: 9.6%Gartner: 100.0%100.0%Indoctrination-26.9 ptsWriter: 26.9%Gartner: 0.0%0.0%Biased Writer Voice-26.5 ptsWriter: 26.5%Gartner: 0.0%0.0%Unattributed Quote-1.7 ptsWriter: 1.7%Gartner: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.