Safety

Multi-vendor AI review agents hang up in costly disagreement over CVE-2026-LGTM

A hypothetical incident report by Andrew Nesbitt describes a dispute between two competing AI review agents attached to a downstream pull request for the foxhole-lz4 package.

Multi-vendor AI review agents hang up in costly disagreement over CVE-2026-LGTM

A hypothetical incident report by Andrew Nesbitt describes how two competing AI review agents attached to a downstream pull request for the foxhole-lz4 package became locked in a disagreement over whether the package was malicious. The dispute produced 340 comments and $41,255 in inference costs; Finance revoked both API keys as a result. One vendor’s marketing team, copied on the cost-anomaly alert, issued a press release citing “a 430% YoY increase in adversarial multi-agent security reasoning,” and the vendor’s stock opened up 6%.

Incident details

  • When: the report frames the event on Day 2 at 16:00 UTC.
  • What was affected: a downstream pull request that bumped the foxhole-lz4 package.
  • Who was involved: two AI review agents from competing vendors, each attached to the same pull request, which came to opposing conclusions about the package’s maliciousness.

Consequences and costs

  • The interaction generated a total of 340 comments.
  • Inference spending totaled $41,255.
  • The Finance team revoked both API keys in response to the anomalous costs.
  • A vendor’s marketing team that had been cc’d on the cost-anomaly alert issued a press release claiming a “430% YoY increase in adversarial multi-agent security reasoning.”
  • According to the report, the vendor’s stock opened 6% higher.

Why this matters

The report illustrates that introducing multiple automated review agents into a software supply chain can create operational and financial risks: unexpected cost escalation, workflow disruption, and coordination challenges between vendors and internal teams. It also highlights the role of cost monitoring and API access controls as defensive measures when automated systems scale in unanticipated ways.

Note on the source

The account is drawn from a speculative, illustrative incident report by Andrew Nesbitt; its purpose is to demonstrate mechanisms and possible outcomes rather than to document a verified, real-world security breach.